ash_phoenix is vulnerable to Incorrect Authorization
76
High Risk
AshPhoenix.LiveView.SubdomainHook runs its handle_subdomain callback during on_mount, before the tenant is assigned. The tenant is only assigned later when LiveView calls handle_params, so the callback and any authorization it performs receive a nil tenant instead of the real one. Tenant-scoped access checks therefore never validate the actual tenant, permitting cross-tenant access. The fix runs handle_subdomain with the real tenant in handle_params.
You are affected if you are using a version that falls within the vulnerable range and you rely on AshPhoenix.LiveView.SubdomainHook with a handle_subdomain callback for tenant-scoped authorization.
ash_phoenix is vulnerable to Incorrect Authorization in versions 2.1.26 - 2.3.24.
Upgrade the ash_phoenix library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.