CVE-2025-48043

Summary

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2.

This issue affects ash: from 0.1.0 before 3.6.2.

Affected Software

VendorProductVersion RangeStatus
ash-projectash0.1.0 < 3.6.2affected
ash-projectash4c41344126b0aba09ec3085517000f8aefec299e < 66d81300065b970da0d2f4528354835d2418c7aeaffected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References