SCA: security update for avo (GHSA-qc5p-3mg5-9fh8)

high Tenable Self-Hosted Container Security Plugin ID 440815

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access
control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action
lookup logic, an authenticated user can execute any Action class (descendants of Avo::BaseAction) on any
resource, even if the action is not registered for that specific resource. This leads to Privilege
Escalation and unauthorized data manipulation across the entire application. This issue has been patched
in version 3.31.2. (CVE-2026-42205)

Solution

Update the avo library and its related packages to version 3.31.2 or later.

See Also

https://github.com/advisories/GHSA-qc5p-3mg5-9fh8

Plugin Details

Severity: High

ID: 440815

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 4/24/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.83

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-42205

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/24/2026

Vulnerability Publication Date: 4/24/2026

Reference Information

CVE: CVE-2026-42205