Am I affected?

type your ash_sql version to check

Description

Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort.

AshSql.Join.related_query/3 skips the caller-supplied exists predicate for such relationships and delegates it to limit_from_many/5. When the relationship's own filter or sort references parent(...), limit_from_many/5 takes a branch that drops both the limit and the predicate, emitting a bare correlated EXISTS with no predicate. The check then matches any record that has any related row. Most severely, when the expression backs a policy (for example authorize_if expr(exists(memberships, user_id == ^actor(:id)))), the actor-scoping condition disappears and the policy passes for any actor with any related row.

This issue affects ash_sql: from 0.4.1 before 0.7.1.

Weaknesses & attack patterns

Weakness

CWE-863 · Incorrect Authorization in catalog → MITRE ↗

Attack patterns

CAPEC-1 · Accessing Functionality Not Properly Constrained by ACLs MITRE ↗

Affected — Hex / ash_sql Hex.pm ↗ Repository ↗

0.4.1 < 0.7.1 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshSql.Join'
source files lib/join.ex
routines 'Elixir.AshSql.Join':related_query/3 · 'Elixir.AshSql.Join':limit_from_many/5

Affected — GitHub / ash-project/ash_sql Repository ↗

e26a63b < 865fdd4 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshSql.Join'
source files lib/join.ex
routines 'Elixir.AshSql.Join':related_query/3 · 'Elixir.AshSql.Join':limit_from_many/5

Configurations

An application must use exists/2 (in a filter or a policy) over a relationship that declares both a limit or from_many? and a filter or sort that references parent(...). The predicate supplied to exists/2 is the one that is dropped.

References

Credits

Peter Ullrich Finder Reporter
Zach Daniel / Ash Project Remediation developer
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
« All CVEs