ash_admin is vulnerable to Query Parameter Injection
20
Low Risk
AshAdmin builds row-action navigation links by interpolating a record's string primary key directly into the query string without URL-encoding it. A primary key value containing query-string metacharacters injects additional parameters into the generated link. Because later parameters win when the query string is parsed, the injected values can override the intended action an admin follows from the data table. The fix URL-encodes row-action link parameters.
You are affected if you are using a version that falls within the vulnerable range and you expose AshAdmin resources with string primary keys whose values can contain user-controlled characters.
ash_admin is vulnerable to Query Parameter Injection in versions 0.4.0 - 1.3.0.
Upgrade the ash_admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.