Am I affected?
type your ash_authentication_phoenix version to check
Description
Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking.
This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex.
This issue affects ash_authentication_phoenix until 2.10.0.
Weaknesses & attack patterns
Weakness
CWE-613
·
Insufficient Session Expiration
in catalog →
MITRE ↗
Attack patterns
CAPEC-593
·
Session Hijacking
MITRE ↗
Affected — Hex / ash_authentication_phoenix Hex.pm ↗ Repository ↗
≥
1.0.0
<
2.10.0
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
source files
source files
lib/ash_authentication_phoenix/controller.ex
Affected — GitHub / team-alembic/ash_authentication_phoenix Repository ↗
≥
de3ecd6
<
a3253fb
affected
every other version:
unaffected
default status
unaffected
cpe
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
source files
source files
lib/ash_authentication_phoenix/controller.ex
References
Credits
James Harton
Remediation reviewer
Zach Daniel
Remediation developer
Mike Buhot
Analyst
Jonatan Männchen / EEF
Analyst
Josh Price
Analyst
CVSS breakdown
LOW 2.3
open in calculator →
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N