Impact
A flaw in the ash_authentication library prevents the session identifier from being regenerated during authentication. An attacker who can plant a valid session ID in a victim’s browser can cause that session ID to survive the login process, allowing the attacker to assume the victim’s identity once the victim authenticates. This can compromise confidentiality, integrity, and availability of user accounts. The weakness is listed as CWE‑384.
Affected Systems
The vulnerability exists in the ash_authentication library from team‑alembic. All releases from 0.2.0 up to but not including 4.15.0, and from 5.0.0‑rc.0 up to but not including 5.0.0‑rc.14, are affected.
Risk and Exploitability
The CVSS score of 7.4 indicates a high risk, while the EPSS score of less than 1% suggests the exploitation probability is currently low. The issue is not yet listed in CISA’s KEV catalog. The likely attack vector involves an attacker influencing the victim’s browser—e.g., through phishing or malicious links—to set a session cookie, making the attack feasible but primarily indirect. Because the flaw allows session hijacking, the impact can be significant for high‑traffic or sensitive applications if the vulnerability is actively exploited.
OpenCVE Enrichment