PT-2026-84093 · Ash · Ash
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash versions 3.0.0-rc.17 through 3.32.1
Description
The software fails to handle exceptions securely during the execution of an Ash.Reactor change step. When a guard controlling a change is evaluated in the
apply where clauses/3 function within Ash.Reactor.ChangeStep, any raised exception is rescued and treated as a condition that was not met. This causes the system to bypass the change entirely instead of halting the process. Consequently, if an attacker provides specific input that triggers an exception in the guard, security-relevant modifications intended to be enforced by that change are skipped, leading to a failing open scenario.Recommendations
Update ash to version 3.32.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash