ash_paper_trail is vulnerable to Sensitive Information Disclosure
59
Medium Risk
AshPaperTrail generates a version resource whose changes map stores the values of tracked attributes. The transformer computed the sensitive? flag for that changes attribute from ignore_attributes instead of the attributes actually persisted, so with the default empty ignore list the flag was always false. As a result the changes map was declared public and non-sensitive even when it held values copied from sensitive? attributes, exposing secrets such as tokens, password hashes, and PII through the version resource's default read action, logs, inspect output, and error messages. The fix computes sensitivity from the tracked attributes so the changes attribute is marked sensitive when it can contain sensitive data.
You are affected if you are using a version that falls within the vulnerable range and you version resources that have attributes marked sensitive?.
ash_paper_trail is vulnerable to Sensitive Information Disclosure in versions 0.1.1 - 0.6.0.
Upgrade the ash_paper_trail library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.