Impact
Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign‑out to remain usable afterwards. The default sign_out/2 routine only clears the server session but does not revoke stored session or bearer tokens, meaning a token obtained before sign‑out remains valid until its own expiration. This flaw permits an attacker who obtains such a token—through script injection, interception, or device theft—to continue authenticating, effectively enabling session hijacking. The weakness aligns with CWE-613, which indicates improper removal or invalidation of a credential after its intended use.
Affected Systems
The flaw affects the Ash Authentication Phoenix library from the Ash Project. All releases up to and including version 2.10.0 are impacted. Organizations using this library in any environment—web or otherwise—are at risk unless the software is upgraded beyond version 2.10.0.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, reflecting that the vulnerability does not directly provide remote code execution or full system takeover. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and, as of now, the issue is not listed in CISA’s KEV catalog. An attacker would need to acquire a valid session token beforehand, typically through script injection, interception of traffic, or device theft, after which the token can be reused after the user logs out. Once in possession of the token, the attacker can replay the session until the token expires, highlighting the importance of proper session revocation at logout.
OpenCVE Enrichment
EUVD
Github GHSA