以下是该漏洞描述信息的中文翻译: 动态确定对象属性控制不当漏洞存在于 ash-project ash 中,允许用户在批量删除(bulk destroy)和批量更新(bulk update)路径中设置私有操作参数的值。 使用 声明的操作参数本应仅由可信的服务器端代码设置(例如通过 ),并且不能由终端用户输入设置。CVE-2026-55736 修复了非批量更改集路径中从用户提供的参数映射中剥离私有参数的问题,但批量删除和批量更新路径未受到保护。 和 会将调用者提供的参数映射中的每个键与操作的所有参数进行匹配,且未进行
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ash-project | ash | 2.17.15< 3.33.11 |
affected |
8c17434803b2e91de522bdfbd0ca918e5d5898df< 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ash-project | ash | 2.17.15 ~ 3.33.11 |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| ash-project | ash | 8c17434803b2e91de522bdfbd0ca918e5d5898df ~ 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f |
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet