ash_typescript is vulnerable to Information Exposure Through an Error Message
63
Medium Risk
The ash_typescript RPC error path uses a configured error_handler to redact or drop errors before they reach clients. When the handler has no clause for an error shape, it raises FunctionClauseError, and the rescue path returns the original unredacted error map, including secrets in its vars. A caller can send requests that produce those unhandled error classes and leak the unredacted errors. The fix does not return the original error when the handler crashes.
You are affected if you are using a version that falls within the vulnerable range and you configure a custom RPC error_handler.
ash_typescript is vulnerable to Information Exposure Through an Error Message in versions 0.8.0 - 0.17.3.
Upgrade the ash_typescript library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.