Am I affected?

type your ash_paper_trail version to check

Description

Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes.

AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes map, which is declared public? true and sensitive? false, so the values are returned by the version resource's default read action and printed in logs, inspect output, and error messages instead of being redacted. AshPaperTrail.Resource.Transformers.CreateVersionResource derives the changes map's sensitivity from the ignore_attributes list (the attributes excluded from changes) rather than from the tracked attributes actually stored in it, and ignore_attributes defaults to empty, so the flag is effectively always false.

This issue affects ash_paper_trail: from 0.1.1 before 0.7.0.

Weaknesses & attack patterns

Weakness

CWE-312 · Cleartext Storage of Sensitive Information in catalog → MITRE ↗

Attack patterns

CAPEC-37 · Retrieve Embedded Sensitive Data MITRE ↗

Affected — Hex / ash_paper_trail Hex.pm ↗ Repository ↗

0.1.1 < 0.7.0 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_paper_trail:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshPaperTrail.Resource.Transformers.CreateVersionResource'
source files lib/resource/transformers/create_version_resource.ex
routines 'Elixir.AshPaperTrail.Resource.Transformers.CreateVersionResource':transform/1

Affected — GitHub / ash-project/ash_paper_trail Repository ↗

e379ca9 < 90efdb0 affected
every other version: unaffected
cpe cpe:2.3:a:ash-project:ash_paper_trail:*:*:*:*:*:*:*:*
modules · source files · routines
modules 'Elixir.AshPaperTrail.Resource.Transformers.CreateVersionResource'
source files lib/resource/transformers/create_version_resource.ex
routines 'Elixir.AshPaperTrail.Resource.Transformers.CreateVersionResource':transform/1

Configurations

The tracked resource must declare one or more sensitive? attributes that are not listed in ignore_attributes. Exposure requires read access to the generated version resource, which ships with defaults [:read, ...] and a changes field that is selectable by default.

References

Credits

Zach Daniel / Ash Project Remediation developer
Peter Ullrich Finder Reporter
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
« All CVEs