CVE-2026-81322
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-200
Revelación de información
Fecha de publicación:
30/08/2026
Última modificación:
30/08/2026
Descripción
*** Pendiente de traducción *** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.<br />
<br />
AshCloak.Transformers.SetUpEncryption removes each cloaked attribute from the action&#39;s accept list and adds an action argument that carries the plaintext into the encryption change. That argument is built with sensitive?: attr.sensitive?, inheriting the flag from the source attribute, so a cloaked attribute declared without sensitive? true produces a non-sensitive argument. It is the only place the cleartext value lives, and the one place Ash will not redact: it appears verbatim in inspect(changeset), Ash.Error.Invalid and validation error messages, telemetry, :sys dumps, and error-tracker payloads. The generated encrypted attribute and decrypt calculation are already hardcoded sensitive.<br />
<br />
This issue affects ash_cloak: from 0.1.0 before 0.4.0.
Impacto
Puntuación base 4.0
2.10
Gravedad 4.0
BAJA



