Impact
The vulnerability is an Incorrect Authorization flaw within the Ash framework that permits an attacker to bypass authentication. The flaw arises when the system incorrectly respects policy checks, allowing unauthenticated requests to proceed. This weakness directly leads to unauthorized access and represents a significant threat to confidentiality and integrity.
Affected Systems
All Ash framework releases from version 0.1.1 up to, but not including, 3.6.2 are affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1 % suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, meaning no public exploits are known. The likely attack vector is inferred to be through exposed API endpoints or custom policy configurations that are incorrectly validated, enabling an attacker to bypass authentication without additional privileges.
OpenCVE Enrichment
Github GHSA