Impact
The vulnerability in AshAuthentication allows an unconfirmed user to obtain a session, bypassing the mandatory email confirmation requirement, due to an improper enforcement of the require_confirmed_with attribute. This is a typical authentication bypass identified as CWE-305 and results in unauthorized access.
Affected Systems
Affected is the AshAuthentication library from team-alembic. Versions from 4.3.8 up to (but not including) 4.15.0 and 5.0.0-rc.0 up to (but not including) 5.0.0-rc.14 are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. No EPSS data is provided, but the vulnerability can be exploited via API calls that invoke the action directly (e.g., through AshGraphql or AshJsonApi). The KEV status is not listed, so no known exploitation campaign is reported. Attackers with access to the API can bypass email confirmation, sign in, and gain unauthorized sessions.
OpenCVE Enrichment