ash_admin is vulnerable to Authorization Bypass Through User-Controlled Key
23
Low Risk
AshAdmin decodes composite primary keys from a request-supplied encoded value and uses the decoded map as filter conditions without checking that its keys are actual primary-key fields. Supplying alternate field names, such as a secret token attribute, turns a record-lookup route into an equality oracle. Observing whether a record is returned reveals whether the guessed value matches, allowing sensitive attribute values to be brute-forced. The fix rejects non-primary-key fields when decoding composite primary keys.
You are affected if you are using a version that falls within the vulnerable range and you expose AshAdmin resources whose records can be looked up through externally supplied primary-key parameters.
ash_admin is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.1.0 - 1.3.0.
Upgrade the ash_admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.