PT-2026-94292 · Unknown · Ashauthentication+1
CVSS v4.0
7.2
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication phoenix versions 1.7.0 through 2.17.3
ash authentication phoenix versions 3.0.0-rc.0 through 3.0.0-rc.10
ash authentication versions 3.10.5 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
An issue in AshAuthenticationPhoenix allows an attacker with access to access logs, proxy logs, or browser history to recover a single-use sign-in token and authenticate as the token owner. This occurs because
AshAuthentication.Phoenix.Components.Password.SignInForm constructs the sign in with token path using the user. metadata .token as a query parameter and performs a GET redirect. Consequently, the token is recorded in the request line by web servers, reverse proxies, and browser history, exposing a live credential in locations that are typically less secure than session storage.Recommendations
Update ash authentication phoenix to version 2.17.4 or later.
Update ash authentication phoenix to version 3.0.0-rc.11 or later.
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication
Ash Authentication Phoenix