Ash Project

Ash

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 23.06.2026 18:21:13
  • Zuletzt bearbeitet 23.06.2026 19:17:12

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is intended to be controlled only by trusted server-side code. Action ar...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 02.04.2026 17:42:26
  • Zuletzt bearbeitet 13.04.2026 18:37:04

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.concat([value]) for any user-supplied binary string that...

  • EPSS 0.81%
  • Veröffentlicht 17.10.2025 13:52:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash:...

  • EPSS 0.47%
  • Veröffentlicht 10.10.2025 15:57:29
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. ...

  • EPSS 0.29%
  • Veröffentlicht 07.09.2025 16:01:01
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib...