Impact
A flaw in AshAuthentication and AshAuthentication Phoenix causes the jti portion of a session identifier to be ignored during authentication. Because the revocation record is never consulted, a session that has been signed out remains fully authenticated. This allows an attacker who obtains a valid session token before revocation to maintain access to protected resources after the legitimate user has logged out, effectively bypassing the intended session invalidation. The vulnerability represents a severe authentication bypass, enabling unauthorized persistence of access for the lifetime of the session.
Affected Systems
The issue affects team‑alembic AshAuthentication from versions 4.9.1 up to but not including 4.15.0 and from 5.0.0‑rc.0 up to but not including 5.0.0‑rc.14. Contained within team‑alembic AshAuthentication Phoenix, the vulnerability exists in versions 2.10.0 through 2.17.3 and in 3.0.0‑rc.0 through 3.0.0‑rc.10. All other versions are unaffected.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is classified as critical. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the high severity score indicates a high likelihood of exploitation if a valid session token is captured. The attack vector is remote, relying on an attacker’s possession of an active session id. Once a session has been captured, the revocation mechanism does not prevent further use, allowing the attacker to maintain uninterrupted access to the affected application.
OpenCVE Enrichment