Impact
The flaw in the Ash library is an incorrect authorization vulnerability that allows an attacker to bypass access control checks and gain unauthorized capabilities. This weakness, classified under CWE‑863, can lead to unauthorized manipulation of resources, affecting the confidentiality, integrity, and availability of the system the library supports.
Affected Systems
The issue applies to all releases of the ash library from version 0.1.1 up through 3.5.39, as indicated in the vulnerability data. Affected builds include any software packaging or deploying the Ash library in that version range.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, representing moderate‑to‑high severity. Because the EPSS score is listed as less than 1 %, the likelihood of public exploitation is low. It is not currently tracked in the CISA KEV catalog. The description implies that the flaw is triggered by requests to an Ash‑based service, suggesting the attack would be executed over the network; however, this inference is drawn from the context rather than an explicit statement in the data.
OpenCVE Enrichment
EUVD
Github GHSA