PT-2026-95162 · Unknown · Ashauthentication
CVSS v4.0
7.4
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 0.2.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
A session fixation issue allows an attacker to maintain an authenticated session if they can plant a session identifier in a victim's browser before the victim signs in. This occurs because the function
store in session/2 in AshAuthentication.Plug.Helpers uses Plug.Conn.put session/3 to write the authenticated subject without calling Plug.Conn.configure session(renew: true), causing the pre-authentication identifier to persist. This affects the default success/4 function in AshAuthentication.Phoenix.Controller. using /1, the AuthController from mix ash authentication phoenix.install, and remember-me auto-login. Additionally, the clear session/2 function uses Plug.Conn.clear session/1, which removes session content but keeps the identifier, allowing a planted ID to survive a logout-then-login sequence. In deployments using server-side session stores (such as ETS, Mnesia, Redis, or a database), this can lead to full account takeover. This is possible if the attacker can plant a cookie via sibling subdomain cookie tossing, an HTTP host without HSTS, or a shared browser.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
As a temporary workaround, call
Plug.Conn.configure session(conn, renew: true) within the success/4 function before store in session/2 is called.
As a temporary workaround, add Plug.Conn.configure session(conn, drop: true) during the sign-out process to ensure planted identifiers are removed.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication