PT-2026-94300 · Unknown · Ashauthentication
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.2.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
An unauthenticated attacker can forge application log entries by submitting a password reset identity containing newlines or control characters. The function
AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the identity variable, which contains the email or username from the reset request, into Logger.warning/1 heredocs without escaping, truncating, or type-restricting it. Because a newline in the identity variable ends the log record, any subsequent text is written as a new line, allowing an attacker to manipulate the severity tag and the content of entries to make them appear as if they originated from the application.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication