Ash Framework是Ash Framework组织的一款基于Elixir的开发框架。 Ash Framework 0.10.0版本至3.33.0之前版本存在输入验证错误漏洞,该漏洞源于对输入指定数量验证不当,使用Elixir String.length/1按Unicode字素计算字符串长度,导致攻击者可绕过长度限制,在受限属性中存储任意大小的值,造成存储无限增长。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ash-project | ash | 0.10.0< 3.33.0 |
affected |
05848d5f4affe60fddd812222a18ada080c0813b< * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 0.10.0 ~ 3.33.0 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | 05848d5f4affe60fddd812222a18ada080c0813b ~ * |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet