ash_phoenix is vulnerable to Exposure of Sensitive Information
23
Low Risk
AshPhoenix.Form.Auto builds an error for an unknown _union_type value submitted in a form by inspecting the entire raw param map for that form. Passwords, tokens and other secrets submitted alongside the union field are written verbatim into the exception message, which reaches logs, crash reports and the development error page. This bypasses Phoenix filter_parameters redaction. The fix stops emitting the raw submitted params in that error.
You are affected if you are using a version that falls within the vulnerable range and you use AshPhoenix.Form auto-generated union forms that accept a user-submitted _union_type value.
ash_phoenix is vulnerable to Exposure of Sensitive Information in versions 1.2.17 - 2.3.24.
Upgrade the ash_phoenix library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.