ash is vulnerable to Mass Assignment
59
Medium Risk
Ash's bulk destroy and bulk update actions build their base changeset by matching every key in the caller-supplied parameter map against all of an action's arguments, with no check for public?: false. A caller that can submit parameters to a bulk destroy or update action can therefore set a private argument that feeds an arg(...) template used by a change or validation, overriding a value the application intended to control only server-side. This is the bulk-path analog of an earlier fix that added the same check to the non-bulk changeset path. The fix requires arg.public? before an argument name is matched against user-supplied input in both bulk base_changeset functions.
You are affected if you are using a version that falls within the vulnerable range and you define a private (public?: false) argument on a bulk destroy or update action that a change or validation references through an arg(...) template.
ash is vulnerable to Mass Assignment in versions 2.17.15 - 3.33.10.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.