Intel

AIKIDO-2025-10297

maintenance_tasks is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE

18

Low Risk

This Affects:

RUBYmaintenance_tasks
1.0.0 - 2.11.0
Fixed in 2.12.0

TL;DR

Affected versions of this package are vulnerable to exposure of sensitive information. Some maintenance tasks require sensitive data in their arguments, but this data may be visible in the UI after the task is submitted. The patch addresses this by introducing a new class method that masks sensitive attributes, ensuring they are hidden from the arguments list displayed in the UI.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

maintenance_tasks is vulnerable to Exposure of Sensitive Information in versions 1.0.0 - 2.11.0.

How to fix this

Upgrade the maintenance_tasks library to the patch version.

Background Info