目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-86338— Ash 字段策略过滤缺陷信息泄露漏洞

一分钟漏洞结论

影响对象
ash-project ash
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: Ash 的字段策略(field policies)旨在防范基于过滤器的信息泄露:当某个执行者(actor)无权查看的字段在过滤器中被引用时,该字段会被替换为一个求值为 nil 的表达式,从而确保过滤器无法被用作“是/否”预言机(oracle),来推断执行者无权查看的字段值。 然而,这种将值置为 nil 的处理仅应用于属性(attributes),而未应用于计算字段(calculations)或聚合字段(aggregates)。用户提供的、引用计算字段或聚合字段的过滤器,其中携带的是

CVSS 6.0 · Medium EPSS 0.43% · P35

影响版本矩阵 2

厂商产品 版本范围状态
ash-project ash 2.11.0-rc.0< 3.33.4 affected
0b6d93c7c4637280b46ae66ea1d2eaf013701238< b3d4503241f3deacb5ceb955e10a4fa927da0f67 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-86338 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle
来源: CVE Program / CVE List V5
Vulnerability Description
Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used as a yes/no oracle to read a value the actor cannot see. This nilling was applied to attributes but not to calculations or aggregates. A user-supplied filter reference to a calculation or aggregate carries an Ash.Query.Calculation / Ash.Query.Aggregate struct, which the authorizer's reference replacement did not match (it only matched the Ash.Resource.* structs), so the filter ran against the real value. As a result, an actor whose field policies forbid a calculation or aggregate can still filter by it (for example filter(secret_calc == "x") or filter(comment_count == n)) and learn the value from whether rows match — an oracle that recovers field-policy-protected values one probe at a time. Filtering is commonly exposed to lower-privileged actors (for example via AshGraphql or AshJsonApi filter arguments), which is exactly the surface field policies are meant to protect. The fix routes filter references to calculations and aggregates through the same field-policy nilling as attributes. This issue affects ash: from 2.11.0-rc.0 before 3.33.4.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
CWE-1220
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ash-project ash 2.11.0-rc.0 ~ 3.33.4 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash 0b6d93c7c4637280b46ae66ea1d2eaf013701238 ~ b3d4503241f3deacb5ceb955e10a4fa927da0f67 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-86338 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-86338 的情报信息

请登录查看更多情报信息。

CVE-2026-86338 补丁与修复 (1)

CVE-2026-86338 其他参考 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86338

暂无评论


发表评论