PT-2026-93377 · Ash · Ash
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash versions 2.11.0-rc.0 through 3.33.3
Description
Field policies are intended to prevent information disclosure by replacing fields an actor cannot see with a
nil expression when used in a filter, preventing the filter from acting as a yes/no oracle. However, this mechanism was only applied to attributes and not to calculations or aggregates. Because user-supplied filter references to calculations or aggregates use Ash.Query.Calculation or Ash.Query.Aggregate structs, they bypassed the authorizer's reference replacement which only matched Ash.Resource.* structs.Consequently, an actor forbidden from accessing a calculation or aggregate can still filter by it, allowing them to deduce protected values based on whether rows match. This is particularly risky when filtering is exposed to lower-privileged actors via AshGraphql or AshJsonApi filter arguments.
Recommendations
Update ash to version 3.33.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash