ash is vulnerable to Incorrect Authorization
59
Medium Risk
Ash's resolve_parent_in_filter/3 silently replaces a failed parent(...) filter evaluation with nil instead of returning an error, so a no_attributes?: true relationship's scoping filter degrades from an equality check into an IS NULL check. Applications that expose a parent(...) filter over an HTTP boundary return other tenants' records whenever the referenced parent attribute is not selected on the source query, because the degraded filter matches on absence rather than on the caller's own scope. The fix makes the evaluation failure raise instead of falling back to nil.
You are affected if you are using a version that falls within the vulnerable range and you expose a no_attributes?: true relationship whose filter uses parent(...) over an HTTP boundary.
ash is vulnerable to Incorrect Authorization in versions 3.13.2 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.