eef-cve-2025-48044

CVSS 8.6 osv_hex
Description

## Summary Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://cna.erlef.org/osv/EEF-CVE-2025-48044.json"
      },
      "package": {
        "ecosystem": "Hex",
        "name": "ash",
        "purl": "pkg:hex/ash"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.6.3"
            },
            {
              "fixed": "3.7.1"
            }
          ],
          "type": "SEMVER"
        }
      ],
      "versions": [
        "3.6.3",
        "3.7.0"
      ]
    },
    {
      "database_specific": {
        "source": "https://cna.erlef.org/osv/EEF-CVE-2025-48044.json"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "79749c2685ea031ebb2de8cf60cc5edced6a8dd0"
            },
            {
              "fixed": "8b83efa225f657bfc3656ad8ee8485f9b2de923d"
            }
          ],
          "repo": "https://github.com/ash-project/ash",
          "type": "GIT"
        }
      ],
      "versions": [
        "v3.7.0",
        "v3.6.3"
      ]
    }
  ],
  "aliases": [
    "CVE-2025-48044",
    "GHSA-pcxq-fjp3-r752"
  ],
  "credits": [
    {
      "name": "Jechol Lee",
      "type": "FINDER"
    },
    {
      "name": "Jechol Lee",
      "type": "REMEDIATION_DEVELOPER"
    },
    {
      "name": "Jonatan Männchen / EEF",
      "type": "ANALYST"
    },
    {
      "name": "Zach Daniel",
      "type": "REMEDIATION_REVIEWER"
    }
  ],
  "database_specific": {
    "capec_ids": [
      "CAPEC-115"
    ],
    "cpe_ids": [
      "cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
    ],
    "cwe_ids": [
      "CWE-863"
    ]
  },
  "details": "## Summary\n\nIncorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1.",
  "id": "EEF-CVE-2025-48044",
  "modified": "2026-09-22T09:45:03.767240120Z",
  "published": "2025-10-17T13:52:53.644Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752"
    },
    {
      "type": "WEB",
      "url": "https://cna.erlef.org/cves/CVE-2025-48044.html"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ash-project/ash/commit/79749c2685ea031ebb2de8cf60cc5edced6a8dd0"
    },
    {
      "type": "FIX",
      "url": "https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d"
    },
    {
      "type": "PACKAGE",
      "url": "https://hex.pm/packages/ash"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Authorization bypass when bypass policy condition evaluates to true"
}
View JSON API Download JSON