U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-22411

Change History

CVE Modified by GitHub, Inc. 1/19/2024 1:15:08 PM

Action Type Old Value New Value
Changed Description
Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12 any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.0.0 release of Avo. Users are advised to upgrade.
Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/avo-hq/avo/commit/51bb80b181cd8e31744bdc4e7f9b501c81172347 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/avo-hq/avo/commit/fc92a05a8556b1787c8694643286a1afa6a71258 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/avo-hq/avo/releases/tag/v2.47.0 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/avo-hq/avo/releases/tag/v3.3.0 [No types assigned]