ash-project 中的 存在输出编码或转义不当的漏洞,允许未经身份验证的攻击者向 挑战头中注入任意认证参数。 和 通过将从请求租户派生的 URL 直接内插到引号包围的值中,从而构建 挑战字符串。在从请求控制的数据(如子域名、Host 头、路径片段或 HTTP 头)设置 Ash 租户的多租户应用中,如果租户值包含双引号 ,就会提前结束引号包围的值,并允许攻击者追加其选择的认证参数,包括一个指向攻击者控制的授权服务器的第二个 URL,符合规范的客户端会遵循该 URL。回车符和换行符会被 Plug 拒绝,因此这是单
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash_authentication_oauth2_server | 0.1.3 ~ 0.3.1 |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| ash-project | ash_authentication_oauth2_server | 99de0a1cacb5ef667c4533278b7c81ca98c00231 ~ 09f97476715da031b136eaec7b2cda2363ad8149 |
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82753 | 8.2 HIGH | Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c |
| CVE-2026-82586 | 8.2 HIGH | AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at |
| CVE-2026-82755 | 6.3 MEDIUM | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab |
| CVE-2026-82758 | 6.3 MEDIUM | ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat |
| CVE-2026-82754 | 6.3 MEDIUM | ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas |
| CVE-2026-82757 | 6.3 MEDIUM | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre |
| CVE-2026-82584 | 2.3 LOW | Terminal escape sequence injection in the mix igniter.install confirmation prompt via pack |
| CVE-2026-81638 | 2.1 LOW | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
No comments yet