PT-2026-84088 · Ash · Ash
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 2.17.20 through 3.32.1
Description
The software discloses the stored value of a confirmed field to an actor who fails a confirmation check. This occurs because the atomic implementation of
Ash.Resource.Validation.Confirm in the atomic/2 function (located in lib/ash/resource/validation/confirm.ex) constructs a mismatch error using the field being confirmed. If an actor provides only the confirmation argument and not the field itself, the atomic ref/2 function resolves the value to the current stored value, which is then echoed back in the error message. An actor can exploit this by submitting an intentionally incorrect confirmation to read the actual stored value of a sensitive attribute.Recommendations
Update ash to version 3.32.2 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash