PT-2026-94301 · Unknown+1 · Ashauthentication+1
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.9.1 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
ash authentication phoenix versions 2.10.0 through 2.17.3
ash authentication phoenix versions 3.0.0-rc.0 through 3.0.0-rc.10
Description
Insufficient session expiration allows a revoked session to remain fully authenticated. When a resource is configured with
session identifier :jti and require token presence for authentication? is disabled, the session value is stored as <jti>:<subject>. The functions AshAuthentication.Plug.Helpers.authenticate resource from session/4 and AshAuthentication.Phoenix.LiveSession.on mount/4 use split identifier/2 to discard the jti and pass only the subject to AshAuthentication.subject to user/3. Since the revocation record is not consulted, the revoked state and expiry of the jti are ignored, allowing sessions captured before sign-out to remain active.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Update ash authentication phoenix to version 2.17.4 or later.
Update ash authentication phoenix to version 3.0.0-rc.11 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication
Ash Authentication Phoenix