PT-2026-84096 · Ash · Ash
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash versions 3.4.44 through 3.32.1
Description
An incorrect authorization issue exists where records that should be denied by a runtime read policy are returned to any actor. This occurs when a resource uses an
access type :runtime read policy, which is a check evaluated per record instead of being compiled into a filter. The check result/1 function in lib/ash/policy/authorizer/authorizer.ex fails to properly handle cases where all policy scenarios for a record are impossible; instead of forbidding the record, the system returns it as authorized.Recommendations
Update ash to version 3.32.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash