PT-2026-83503 · Unknown · Ash Paper Trail
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash paper trail versions 0.1.1 through 0.6.9
Description
Sensitive information is stored in cleartext within the generated version resource. An attacker with read access to this resource can recover the plaintext of attributes marked as sensitive. This occurs because the
changes map in the version resource is declared as public and not sensitive, causing values to be returned by the default read action and appearing in logs, inspect output, and error messages without redaction. The AshPaperTrail.Resource.Transformers.CreateVersionResource function incorrectly derives the sensitivity of the changes map from the ignore attributes list instead of the tracked attributes. Since ignore attributes defaults to empty, the sensitivity flag remains false.Recommendations
Update ash paper trail to version 0.7.0 or later.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Paper Trail