logo

Database

Authentication mechanism absence or evasion In ash

Description

Bypass and runtime policies that can never pass may be incorrectly applied in filter authorization

Summary

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2.

This issue affects ash: from 0.1.0 before 3.6.2.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions