Impact
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. The description implies that when a bypass policy condition evaluates to true, the system treats the request as authorized, allowing access to protected resources or privilege escalation and potentially compromising confidentiality and integrity on affected deployments.
Affected Systems
The vulnerability affects the ash conductor component for all versions of ash from pkg:hex/ash@3.6.3 up to but not including pkg:hex/ash@3.7.1. Earlier releases before commit 8b83efa225f657bfc3656ad8ee8485f9b2de923d are also impacted. The impacted product is the Ash framework maintained by the ash-project; systems running any of these versions should treat the application as vulnerable.
Risk and Exploitability
The CVSS score of 8.6 reflects the high impact, yet the EPSS score of < 1% indicates a low current likelihood of exploitation in the wild. The issue is not listed in CISA's KEV catalog. Based on the description, it is inferred that the likely attack vector is an in-application trigger that evaluates a policy condition; once triggered, it permits a bypass of authentication without user interaction, making the vulnerability valuable to attackers.
OpenCVE Enrichment
Github GHSA