ash_admin is vulnerable to Denial of Service (DoS)
83
High Risk
The calculate event handler on the AshAdmin resource show page converts incoming form keys to atoms with an unbounded call that mints a new atom per unique key. Because atoms are never garbage collected, submitting events with many distinct keys grows the VM atom table without limit. Exhausting the atom table crashes the entire BEAM virtual machine and every application running on it. The fix resolves the calculation first and drops form keys that are not declared calculation arguments instead of interning client input.
You are affected if you are using a version that falls within the vulnerable range and untrusted users can reach the AshAdmin resource page that runs ad-hoc calculations.
ash_admin is vulnerable to Denial of Service (DoS) in versions 0.1.0 - 1.3.0.
Upgrade the ash_admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.