PT-2026-94285 · Unknown · Ashauthentication
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 0.2.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
Improper verification of cryptographic signatures in AshAuthentication allows a caller of the token revocation action to neutralize a revocation or write arbitrary rows into the token resource. The function
AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it using AshAuthentication.Jwt.peek/1, which delegates to Joken.peek claims/1 without performing a signature check. Consequently, the jti, exp, and sub claims are written directly to the revocation record. An attacker can provide a forged token with a backdated exp claim, causing the revocation row to be treated as expired and removed by expunge expired, which allows the genuine token to pass the revoked? check. Additionally, arbitrary jti and sub values can be inserted into the resource.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication