Логотип exploitDog
bind:CVE-2025-48042
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48042

Количество 2

Количество 2

nvd логотип

CVE-2025-48042

5 месяцев назад

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a.

EPSS: Низкий
github логотип

GHSA-jj4j-x5ww-cwh9

5 месяцев назад

Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-48042

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a.

0%
Низкий
5 месяцев назад
github логотип
GHSA-jj4j-x5ww-cwh9

Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden

CVSS3: 5.6
0%
Низкий
5 месяцев назад

Уязвимостей на страницу