Intel

AIKIDO-2025-10033

oban_web is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 21, 2025

11

Low Risk

This Affects:

elixiroban_web
2.10.3 - 2.10.6
Fixed in 2.11.0
Are you affected? Scan for Free

TL;DR

The latest version of oban_web enhances security by preventing the decoding of executable functions when displaying recorded output. By default, recorded content now uses the :safe flag, which blocks both atom creation and executable content. This change adds an extra layer of protection against potential exploits.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

oban_web is vulnerable to Exposure of Sensitive Information in versions 2.10.3 - 2.10.6.

How to fix this

Upgrade the oban_web library to the patch version.