ash is vulnerable to Improper Access Control
59
Medium Risk
The ETS and Mnesia data layers write new records without checking whether the primary key already exists. A create action that supplies an existing primary key overwrites the stored record instead of failing. When primary keys are client controlled, create actions can change existing rows even where authorization policies are enforced. The fix rejects duplicate primary keys on create in both data layers.
You are affected if you are using a version that falls within the vulnerable range and you use the ETS or Mnesia data layer with client supplied primary keys on create actions.
ash is vulnerable to Improper Access Control in versions 0.4.0 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.