avo
RubyGems5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting avopage 1 of 1
- CVE-2023-34102HIGHCVSS 8.3EG 8.32023-06-05
vulnerable: 3.0.0.pre1 ... 3.0.0.pre9 (12 versions)
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected…
- CVE-2023-34103HIGHCVSS 7.3EG 7.32023-06-05
vulnerable: 3.0.0.pre1 ... 3.0.0.pre9 (12 versions)
Avo is an open source ruby on rails admin panel creation framework. In affected versions some avo fields are vulnerable to Cross Site Scripting (XSS) when rendering html based content. Attackers do need form edit privilege in order to succ…
- CVE-2024-22191HIGHCVSS 7.3EG 7.3✓ Fixed in 2.47.02024-01-16
vulnerable: 0.2.0 ... 2.9.2.pre1 (345 versions)
Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This vulnerability could allow an attacker to execute arbitrary…
- CVE-2024-22411MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.47.02024-01-16
vulnerable: 0.2.0 ... 2.9.2.pre1 (345 versions)
Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/noti…
- CVE-2026-42205HIGHCVSS 8.8EG 8.8✓ Fixed in 3.31.22026-05-08
vulnerable: 0.2.0 ... 3.9.2 (569 versions)
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action lookup logic, an authenti…
Check whether avo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for avo CVEs against the assets you own.
Start Free Scan →