PT-2026-83691 · Unknown · Ash Phoenix
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash phoenix versions 1.2.17 through 2.3.24
Description
The software writes the entire raw submitted parameter map into an exception message when
AshPhoenix.Form.Auto builds a union sub-form and the submitted union type does not match a configured type. This causes sensitive information, such as secrets submitted alongside a union form field, to leak into logs, crash reports, and development error pages. Because the message is constructed by the library instead of the Phoenix parameter logger, the filter parameters configuration does not redact the data. An attacker can trigger this by submitting an invalid union type along with sensitive data in other parameters, such as password, which will then be included verbatim in the raised message.Recommendations
Update ash phoenix to version 2.3.25 or later.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ash Phoenix