Am I affected?

type your ash_authentication_phoenix version to check

Description

Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking.

This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex.

This issue affects ash_authentication_phoenix until 2.10.0.

Weaknesses & attack patterns

Weakness

CWE-613 · Insufficient Session Expiration in catalog → MITRE ↗

Attack patterns

CAPEC-593 · Session Hijacking MITRE ↗

Affected — Hex / ash_authentication_phoenix Hex.pm ↗ Repository ↗

1.0.0 < 2.10.0 affected
every other version: unaffected
default status unaffected
cpe cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
source files
source files lib/ash_authentication_phoenix/controller.ex

Affected — GitHub / team-alembic/ash_authentication_phoenix Repository ↗

de3ecd6 < a3253fb affected
every other version: unaffected
default status unaffected
cpe cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
source files
source files lib/ash_authentication_phoenix/controller.ex

References

Credits

James Harton Remediation reviewer
Zach Daniel Remediation developer
Mike Buhot Analyst
Jonatan Männchen / EEF Analyst
Josh Price Analyst

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
« All CVEs