Ash Project

Ash

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 12.08.2026 20:04:42
  • Zuletzt bearbeitet 18.08.2026 14:53:39

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. ...

  • EPSS 0.14%
  • Veröffentlicht 09.08.2026 18:17:07
  • Zuletzt bearbeitet 12.08.2026 20:52:13

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is...

  • EPSS 0.13%
  • Veröffentlicht 09.08.2026 18:01:32
  • Zuletzt bearbeitet 18.08.2026 15:38:34

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[...

  • EPSS 0.15%
  • Veröffentlicht 23.06.2026 18:21:13
  • Zuletzt bearbeitet 09.07.2026 16:16:45

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action ar...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 02.04.2026 17:42:26
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that...

  • EPSS 0.81%
  • Veröffentlicht 17.10.2025 13:52:53
  • Zuletzt bearbeitet 24.07.2026 15:17:07

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash:...

  • EPSS 0.46%
  • Veröffentlicht 10.10.2025 15:57:29
  • Zuletzt bearbeitet 24.07.2026 15:17:07

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. ...

  • EPSS 0.31%
  • Veröffentlicht 07.09.2025 16:01:01
  • Zuletzt bearbeitet 24.07.2026 15:17:06

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib...