PT-2026-94295 · Unknown · Ashauthentication
CVSS v4.0
1.8
Low
| Vector | AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.12.0 through 4.14.x
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.1
Description
AshAuthentication allows the disclosure of user password digests to readers of the audit store. The
audit log add-on builds extra data for each entry in the AshAuthentication.AddOn.AuditLog.Auditor.build extra data/4 function, which takes the :actor from the action callback context verbatim. When an audited action is invoked with actor: set to a user record, the record—including the hashed password attribute—is deposited into the audit entry. While other identities are collapsed via AshAuthentication.user to subject/1 and parameters are filtered, the actor remains unfiltered. Setting the attribute sensitive?: true is ineffective as it only redacts inspect/1 output and not JSON encoding or raw-term storage. Exploitation requires independent read access to the audit store (e.g., database credentials, backups, or log shippers), enabling offline password attacks against active accounts. Persistence of this data depends on the data layer; raw-term stores keep it verbatim, whereas SQL stores may drop the entry unless the user resource derives Jason.Encoder.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.2 or later.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication