Vulnerability description

Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking.

This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex.

This issue affects ash_authentication_phoenix until 2.10.0.

Affected

ash-project / ash_authentication_phoenix

Source File
lib/ash_authentication_phoenix/controller.ex
Status Version Changes / Fixed in
affected pkg:hex/ash_authentication_phoenix@0 < pkg:hex/ash_authentication_phoenix@2.10.0
affected 0 < 2.10.0
affected 0 < a3253fb4fc7145aeb403537af1c24d3a8d51ffb1

References

Credits

  • Remediation reviewer: James Harton
  • Remediation developer: Zach Daniel
  • Analyst: Mike Buhot
  • Analyst: Jonatan Männchen
  • Analyst: Josh Price

CVE record as JSON:  GET /cves/cve-2025-4754.json