Impact
The vulnerable plug in the Ash Authentication component permits an attacker to replace a victim’s authenticated session with one belonging to the attacker’s own account through a spoofed remember‑me cookie. The plugin checks a session key that is never written unless a specific configuration flag is enabled, so the key is never found, causing the remember‑me pathway to execute on every request. Consequently any operations performed by the victim after the cookie is planted are attributed to the attacker, compromising both confidentiality and integrity of the application data.
Affected Systems
This flaw exists in the Elixir Ash Authentication module for versions from 4.10.0 up to but not including 4.15.0, and from 5.0.0‑rc.0 up to before 5.0.0‑rc.14. Any system using this module with its default configuration (require_token_presence_for_authentication? false) and the remember‑me plug active is affected.
Risk and Exploitability
The CVSS score of 9.1 marks the vulnerability as a high‑severity authentication bypass. Exploitation requires the attacker to plant a remember‑me cookie in the victim’s browser; based on the description, it is inferred that this could be achieved through XSS or similar cookie injection techniques. The EPSS score of less than 1% indicates a low prevalence of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly available zero‑day exploits. Nevertheless, the impact remains critical for applications that do not enforce the token presence flag or that rely on the remember‑me plug for session restoration.
OpenCVE Enrichment