PT-2026-108749 · Ash · Ash
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 2.6.0 through 3.34.5
Description
An incorrect authorization issue allows an actor to infer data in related records they are not permitted to read. This occurs because the function
Ash.Actions.Aggregate.run/4 only applied the root resource's read policy before executing the aggregate query, skipping the read policies of related resources. A caller can test conditions against hidden related rows to recover their existence and attribute values one query at a time if their filter or sort reaches the Ash.count/2, Ash.exists/2, or Ash.aggregate/3 functions. This can happen through Ash.Query.filter input/2, an ash lua script, or an AshAi tool. This issue is reachable when an application passes caller-supplied filters or sorts that cross a relationship into the affected functions and the related resource's read policy is stricter than the root resource's.Recommendations
Update ash to version 3.34.6 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash