sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitive set from the resource's own attributes and never descend into embedded, union, or list values, so a non-sensitive attribute or action argument that holds an embed with a sensitive? field (for example an accepted credentials embed carrying a token) is written to the version table in cleartext.
This issue affects ash_paper_trail: from 0.3.0 before 0.7.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 30 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitive set from the resource's own attributes and never descend into embedded, union, or list values, so a non-sensitive attribute or action argument that holds an embed with a sensitive? field (for example an accepted credentials embed carrying a token) is written to the version table in cleartext. This issue affects ash_paper_trail: from 0.3.0 before 0.7.0. | |
| Title | Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions | |
| First Time appeared |
Ash-project
Ash-project ash Paper Trail |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:ash-project:ash_paper_trail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Paper Trail |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-30T00:18:22.853Z
Reserved: 2026-08-24T15:45:02.123Z
Link: CVE-2026-77970
No data.
Status : Received
Published: 2026-08-30T01:20:29.773
Modified: 2026-08-30T01:20:29.773
Link: CVE-2026-77970
No data.
OpenCVE Enrichment
Updated: 2026-08-30T01:30:17Z