ash is vulnerable to Incorrect Authorization
21
Low Risk
When a where guard in an Ash.Reactor change step raises, the step skips the change and reports success, the same as a guard that returns false. Untrusted input that makes the guard raise can skip security-relevant changes such as a privilege downgrade, so the action completes as if it succeeded and leaves the record in an unintended state. The fix fails the step closed when a where guard raises.
You are affected if you are using a version that falls within the vulnerable range and you use an Ash.Reactor change step with a where guard on untrusted input.
ash is vulnerable to Incorrect Authorization in versions 3.0.0 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.