Impact
The vulnerability in the Ash framework causes the read policy of related resources to be omitted when executing aggregate, count, or exists operations. This omission lets an attacker apply filters or sort criteria that touch hidden related data, thereby testing conditions against records they cannot normally read. The attacker can then deduce the existence and specific attribute values of those hidden rows one query at a time, leaking confidential information about related resources.
Affected Systems
Systems running Ash versions 2.6.0 through 3.34.5 are susceptible. The issue affects the ash-project:ash product as listed by the CNA and is documented under the CA version range before 3.34.6. No other versions are referenced as affected.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. EPSS is not available, and the vulnerability is not currently listed in CISA KEV, suggesting a lower immediate exploitation probability. The likely attack vector is through legitimate API calls to functions such as Ash.count/2, Ash.exists/2, or Ash.aggregate/3, or via custom scripts that leverage these functions. Once accessed, an attacker can infer sensitive data from related resources, impacting confidentiality without affecting read/authorization counts exposed through Ash.read/2.
OpenCVE Enrichment