Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-75847

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-312 Almacenamiento de información sensible en texto claro
Fecha de publicación:
30/08/2026
Última modificación:
30/08/2026

Descripción

*** Pendiente de traducción *** Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes.<br /> <br /> AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource&amp;#39;s changes map, which is declared public? true and sensitive? false, so the values are returned by the version resource&amp;#39;s default read action and printed in logs, inspect output, and error messages instead of being redacted. AshPaperTrail.Resource.Transformers.CreateVersionResource derives the changes map&amp;#39;s sensitivity from the ignore_attributes list (the attributes excluded from changes) rather than from the tracked attributes actually stored in it, and ignore_attributes defaults to empty, so the flag is effectively always false.<br /> <br /> This issue affects ash_paper_trail: from 0.1.1 before 0.7.0.