ash_paper_trail is vulnerable to Sensitive Information Disclosure
59
Medium Risk
AshPaperTrail can redact or drop attributes marked sensitive? before writing an audit version record. Before the fix the redaction logic only inspected top-level attributes and arguments, so sensitive values nested inside embedded resources, maps, unions, or lists were written verbatim into the version changes and version_action_inputs columns. Applications that relied on sensitive_attributes to protect nested secrets stored them in cleartext in tables that usually have broader read access and longer retention than the source records. The fix recursively redacts sensitive fields in nested values across changes, snapshots, and action inputs.
You are affected if you are using a version that falls within the vulnerable range and you rely on sensitive_attributes in :redact or :ignore mode to protect fields that are nested inside embedded resources, maps, unions, or lists.
ash_paper_trail is vulnerable to Sensitive Information Disclosure in versions 0.3.0 - 0.6.0.
Upgrade the ash_paper_trail library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.