目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-101028— Ash计数存在聚合跳过关联资源读策略漏洞

一分钟漏洞结论

影响对象
ash-project ash
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: ash-project 的 ash 存在一个授权不正确(Incorrect Authorization)漏洞。攻击者可以通过 Ash.count/2、Ash.exists/2 和 Ash.aggregate/3 推断出其无权读取的相关记录中的数据。 在运行聚合查询之前,Ash.Actions.Aggregate.run/4(lib/ash/actions/aggregate.ex)仅应用了根资源(root resource)的读取策略(read policy)。而在正常读取路径中,

CVSS 6.0 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-101028 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts
来源: CVE Program / CVE List V5
Vulnerability Description
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ash-project ash 2.6.0 ~ 3.34.6 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c ~ 80936187b27ee94f15cd875affd3141b5cb23185 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-101028 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-101028 的情报信息

请登录查看更多情报信息。

CVE-2026-101028 其他参考 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101028

暂无评论


发表评论