216.73.216.233

CVE-2025-48044

· Published 17/10/2025 14:15 · Modified 17/10/2025 14:15

Labels: CVE-2025-48044 2025-10-176b3ad84c-e1a6-4bf7-a703-f496b71e49dbCVE-2025-48044CWE-863

Essential information

Published
17/10/2025 14:15
Modified
17/10/2025 14:15
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/[email protected] before pkg:hex/[email protected], from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
NVD
View on NVD

Affected products (CPE)

ProductCPE
ash-project / ash cpe:2.3:a:ash-project:ash:3.6.3-3.7.1:*:*:*:*:*:*:*

References