漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Vulnerability Description
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association through Avo::AssociationsController#create. An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly attach related records to a parent record by sending a crafted POST request, which can lead to privilege escalation and cross-tenant data exposure where associations represent authorization-bearing relationships. This issue is fixed in versions 3.32.1 and 4.0.0.beta.51.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
avo-hq avo 授权问题漏洞
Vulnerability Description
avo-hq avo是avo-hq的根据输入中"category1_names":"其他服务器产品"和"category2_names":"服务器",确认产品为服务器产品,但具体类型不够明确,无法输出更具体的定义短语。 avo-hq avo 3.32.1之前版本和4.0.0.beta.51之前版本存在授权问题漏洞,该漏洞源于关联附加工作流中授权检查不一致,可能导致已认证的低权限用户绕过隐藏或禁用的附加控件,通过特制POST请求直接附加相关记录,从而导致权限提升和跨租户数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A