Am I affected?

type your ash_authentication_phoenix version to check

Description

Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.

The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It never revokes the stored session or bearer tokens, so a token obtained before sign-out, through script injection, interception or device theft, keeps authenticating until its own expiry. Changing the password still revokes it.

This issue affects ash_authentication_phoenix: from 0.1.0 before 2.10.0.

Weaknesses & attack patterns

Weakness

CWE-613 · Insufficient Session Expiration in catalog → MITRE ↗

Attack patterns

CAPEC-593 · Session Hijacking MITRE ↗

Affected — Hex / ash_authentication_phoenix Hex.pm ↗ Repository ↗

≥ 0.1.0 < 2.10.0 affected
every other version: unaffected
cpe cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
version type semver
modules · source files · routines
modules 'Elixir.AshAuthentication.Phoenix.Controller'
source files lib/ash_authentication_phoenix/controller.ex
routines 'Elixir.AshAuthentication.Phoenix.Controller':'__using__'/1

Affected — GitHub / team-alembic/ash_authentication_phoenix Repository ↗

≥ 05ab4f4 < a3253fb affected
every other version: unaffected
cpe cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
version type git
modules · source files · routines
modules 'Elixir.AshAuthentication.Phoenix.Controller'
source files lib/ash_authentication_phoenix/controller.ex
routines 'Elixir.AshAuthentication.Phoenix.Controller':'__using__'/1

References

Credits

James Harton Remediation reviewer
Zach Daniel Remediation developer
Mike Buhot Analyst
Jonatan Männchen / EEF Analyst
Josh Price / Alembic Analyst

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
« All CVEs