Vulnerability description

Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking.

This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex.

This issue affects ash_authentication_phoenix until 2.10.0.

Affected

pkg:hex/ash_authentication_phoenix

Status Type Version Changes / Fixed in
affected semver initial < 2.10.0

pkg:github/team-alembic/ash_authentication_phoenix

Status Type Version Changes / Fixed in
affected git initial < a3253fb4fc71

References

Credits

  • Remediation reviewer: James Harton
  • Remediation developer: Zach Daniel
  • Analyst: Mike Buhot
  • Analyst: Jonatan Männchen
  • Analyst: Josh Price

CVE record as JSON:  GET /cves/CVE-2025-4754.json
OSV record as JSON:  GET /osv/EEF-CVE-2025-4754.json