翻译: ash-project 中 ash_lua 存在“替代路径保护不当”漏洞,允许用户提供的 Lua 脚本读取不在公开字段白名单中的属性。 AshLua 将 Ash 资源暴露给 Lua 脚本,其暴露范围由一个清单(manifest)定义,该清单声明了哪些字段是公开的。然而,AshLua.Runtime 中 read 操作所使用的聚合路径(aggregate path)在解析字段时,直接取自 Lua 调用中的字段名,并通过 和 进行解析,这两个环节均未参考常规字段路径所执行的公开字段白名单。因此,脚本可以读取任何
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_lua | 0.1.0 ~ 0.2.1 |
cpe:2.3:a:ash-project:ash_lua:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_lua | 8675e47cca81f36594083a7e63379bac9e123e72 ~ c0dfcd9494766d548178c37df0bd01cff378e1c7 |
cpe:2.3:a:ash-project:ash_lua:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82754 | 6.3 MEDIUM | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas |
| CVE-2026-82757 | 6.3 MEDIUM | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre |
| CVE-2026-82756 | 6.3 MEDIUM | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti |
| CVE-2026-82584 | 2.3 LOW | Terminal escape sequence injection in the mix igniter.install confirmation prompt via pack |
| CVE-2026-81638 | 2.1 LOW | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
No comments yet