Intel

AIKIDO-2025-10924

rustler_precompiled is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 11, 2025

30

Low Risk

This Affects:

ELIXIRrustler_precompiled
0.1.0 - 0.8.3
Fixed in 0.8.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive data exposure in debug logs due to unredacted credentials in URLs, allowing attackers who gain access to these logs to extract usernames and passwords from userinfo components, potentially leading to unauthorized access to systems or accounts; the patch mitigates this by redacting userinfo with '[REDACTED]' before logging.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

rustler_precompiled is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.0 - 0.8.3.

How to fix this

Upgrade the rustler_precompiled library to the patch version.