Cleartext Storage Vulnerability in ash_paper_trail by Ash Project
CVE-2026-75847
What is CVE-2026-75847?
The ash_paper_trail component of the Ash Project contains a cleartext storage vulnerability, allowing attackers with read access to exposed version resources to potentially recover sensitive information. The vulnerability arises from the improper handling of tracked sensitive attributes, which are incorrectly stored in the changes map and designated as non-sensitive. This oversight permits the disclosure of sensitive values during default read actions, log outputs, and error messages, removing essential redaction and increasing the risk of data exposure. This flaw impacts versions of ash_paper_trail from 0.1.1 to just before 0.7.0.
Affected Version(s)
ash_paper_trail 0.1.1 < 0.7.0
ash_paper_trail e379ca90a0c4db54d07a9d1556fd12f2413f6e98 < 90efdb0769f83f7c5daba6a87758daebf4baf32c
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
