PT-2026-49202 · Unknown · Ashauthentication
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 0.1.0 through 4.13.x
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.9
Description
An authentication bypass by spoofing allows account takeover of local users during OAuth2 or OIDC sign-in. The issue occurs because the software matches local users by email address instead of using the OpenID Connect
iss (issuer) and sub (subject) claim combination, which are the only stable and unique identifiers for an end-user. An unauthenticated attacker can register an account on an accepted OAuth provider using a victim's email—including unverified or reused emails—to gain full local privileges of the victim's account.Recommendations
Update versions 0.1.0 through 4.13.x to version 4.14.0.
Update versions 5.0.0-rc.0 through 5.0.0-rc.9 to version 5.0.0-rc.10.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication