PT-2026-94293 · Hexpm · Ashauthentication
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 0.6.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
Insufficient session expiration allows an attacker who obtains a victim's OAuth2
state value to replay the callback and sign that victim into an attacker-controlled account. The function AshAuthentication.Strategy.OAuth2.Plug.callback/2 fails to clear stored session params during failure paths, such as when the provider returns an access denied error, an invalid code, or a token-exchange error. Because the else block in the Elixir with chain reaches store authentication result/2 while holding the original connection, the session entry is not removed. Consequently, the value intended to protect against Cross-Site Request Forgery (CSRF) is only consumed upon successful authentication and persists after cancelled or failed attempts.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication