Impact
A flaw in AshCloak's encryption setup causes the plain text of a cloaked field to be copied into an action argument that is marked as non‑sensitive when the original attribute is not flagged as sensitive. That argument is the only location where the cleartext survives encryption and is subsequently included verbatim in change sets, validation error messages, telemetry data, system dumps, and error‑tracker payloads, allowing an attacker to recover the original value. The impact is the disclosure of sensitive data that was supposed to be protected by encryption.
Affected Systems
The issue affects the ash-project AshCloak library in all releases from 0.1.0 up to, but not including, version 0.4.0.
Risk and Exploitability
The CVSS score is 2.1, indicating a low severity information‑disclosure flaw. Exploitation requires the ability to trigger a validation error or to read application logs, error trackers, or crash reports, which normally implies local or application‑level access. No exploit has been reported in CISA KEV and the EPSS score is not available, suggesting limited public exploitation. Nonetheless, if an adversary can access logs or crash data, they can obtain plaintext values for encrypted fields.
OpenCVE Enrichment