PT-2026-83548 · Ash Sql · Ash Sql
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash sql versions 0.1.0 through 0.7.0
Description
An incorrect authorization issue allows a caller to receive aggregate values, such as counts, sums, or lists, that should have been excluded by a more restrictive filter. This leads to data disclosure across authorization or tenancy boundaries. The problem occurs in the
different queries?/2 function, which incorrectly identifies two aggregate queries as identical if they share a name and lack different sorts, even if their filters differ. Consequently, when actor or tenant context is applied, a narrowly filtered aggregate may return the value of a previously registered broad aggregate.Recommendations
Update ash sql to version 0.7.1 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Sql