ash-project 中 ash_authentication_oauth2_server 存在“备用路径保护不当”漏洞 在 ash_authentication_oauth2_server 中,由于备用路径缺乏充分保护,导致状态变更型的 OAuth 端点暴露在非预期的 URL 前缀下,从而绕过了仅针对规范前缀设置的控制措施。 具体而言,位于 的 在 前缀和 前缀下都挂载了同一个 。由于 Phoenix 的 机制会在分发前剥离已匹配的前缀,因此完整的路由表会在两个挂载点同时生效。这使得 、 和 也可以分别通过 、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_authentication_oauth2_server | 0.1.0 ~ 0.3.1 |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_authentication_oauth2_server | 855b578037c5ded18e8a6e60f42e56bde4905fae ~ a72972d7ed3eb74c05dfa0653a258ef14454459a |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82586 | 8.2 HIGH | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82757 | 6.3 MEDIUM | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre |
| CVE-2026-82756 | 6.3 MEDIUM | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti |
| CVE-2026-82584 | 2.3 LOW | Terminal escape sequence injection in the mix igniter.install confirmation prompt via pack |
| CVE-2026-81638 | 2.1 LOW | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
No comments yet