Impact
A scripting interface in AshLua lets users execute arbitrary Lua code through an eval action. The read operation exposes an ability to request aggregate functions such as list, min, max, first, sum, and avg on a specified field. Because field‑policy enforcement removes forbidden data only from full record results, it does not apply to aggregate values, allowing scripts to retrieve values from fields that should be hidden by per‑actor policies. This effectively bypasses privacy controls and can expose sensitive personal information that is normally protected.
Affected Systems
AshProject’s AshLua component is affected, with vulnerable releases ranging from version 0.1.0 up to but excluding 0.2.2. The issue applies to all builds of ash_lua within that range.
Risk and Exploitability
The vulnerability scores a CVSS of 6 and the EPSS score is not available, indicating moderate severity and an unclear likelihood of exploitation. The Ash project has not listed it in the CISA KEV catalog. Exploitation requires the ability to run Lua code via eval, typically available to privileged users or an attacker who has compromised an instance of the application. Once a script is executed, the attacker can aggregate over fields that the caller’s policy would otherwise deny, thereby obtaining confidential data from the underlying database or data store.
OpenCVE Enrichment