Ash Authentication 中存在的“通过欺骗绕过身份验证”漏洞,允许能够向受害者浏览器植入 remember-me 令牌的攻击者,将受害者的已认证会话替换为攻击者自己账户的会话。 具体机制如下: 函数本应通过检查会话中是否存在 键来跳过对已登录访客的重新认证。然而, 函数仅在启用了 配置时才会写入该键;否则,它只会写入裸的主体名称(bare subject name)。在默认配置下,该守卫函数(guard)读取的键从未被写入,导致其“已登录”分支永远无法被执行。因此,remember-me 登录逻辑会在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| team-alembic | ash_authentication | 4.10.0 ~ 4.15.0 |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | 3d3de314692558d06ec13945f857f00514e95a8c ~ * |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82761 | 9.1 CRITICAL | Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
| CVE-2026-86533 | 9.1 CRITICAL | Revoked session accepted because the session jti is never checked in AshAuthentication and |
| CVE-2026-85500 | 9.1 CRITICAL | `require_confirmed_with` is not enforced on the action and fails open on an unreadable att |
| CVE-2026-88952 | 9.1 CRITICAL | OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentic |
| CVE-2026-91039 | 9.1 CRITICAL | dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing c |
| CVE-2026-82760 | 8.2 HIGH | Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in |
| CVE-2026-82685 | 7.6 HIGH | Confirmation token accepted on any record in AshAuthentication |
| CVE-2026-80218 | 7.6 HIGH | Sign-in token minted for one resource accepted by another in AshAuthentication |
| CVE-2026-86688 | 7.4 HIGH | Session id is not renewed on authentication in ash_authentication, allowing session fixati |
| CVE-2026-81632 | 7.2 HIGH | Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix |
| CVE-2026-78223 | 6.9 MEDIUM | Token revocation record built from unverified JWT claims in AshAuthentication |
| CVE-2026-86522 | 6.3 MEDIUM | Log injection via an unescaped password reset identity in AshAuthentication |
| CVE-2026-81637 | 2.3 LOW | Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication |
| CVE-2026-82723 | 1.8 LOW | Actor record with password digest stored in AshAuthentication audit log entries |
| CVE-2026-82759 | 1.8 LOW | Reversible IP address pseudonymisation in AshAuthentication audit log hash mode |
No comments yet