Description
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/[email protected] before pkg:hex/[email protected], from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.
INFO
Published Date :
2025-10-17T13:52:53.644Z
Last Modified :
2026-04-16T04:16:08.167Z
Source :
EEF
AFFECTED PRODUCTS
The following products are affected by CVE-2025-48044 vulnerability.
| Vendors | Products |
|---|---|
| Ash-project |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-48044.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability