ash is vulnerable to Information Exposure Through an Error Message
21
Low Risk
The confirm validation uses the stored field value in the atomic mismatch error instead of the submitted confirmation value. When the confirmation does not match, the error message discloses the stored value, including fields protected by field policies. Authenticated users can read data they are not authorized to see by triggering the mismatch. The fix uses the confirmation input instead of the stored value when building the error.
You are affected if you are using a version that falls within the vulnerable range and you use the confirm validation on a field protected by field policies during atomic updates.
ash is vulnerable to Information Exposure Through an Error Message in versions 2.17.20 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.