Логотип exploitDog
bind:CVE-2025-48044
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48044

Количество 2

Количество 2

nvd логотип

CVE-2025-48044

4 месяца назад

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

EPSS: Низкий
github логотип

GHSA-pcxq-fjp3-r752

4 месяца назад

Ash has authorization bypass when bypass policy condition evaluates to true

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-48044

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

0%
Низкий
4 месяца назад
github логотип
GHSA-pcxq-fjp3-r752

Ash has authorization bypass when bypass policy condition evaluates to true

CVSS3: 8.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу