以下是该漏洞描述的中文翻译: 漏洞描述:在 team-alembic 的 AshAuthenticationPhoenix 中,存在“包含敏感查询字符串的 HTTP 请求”漏洞。任何能够读取访问日志、代理日志或浏览器历史记录的人,都能恢复一次性的登录令牌,并以此令牌对应所有者的身份进行身份验证。 在密码登录成功后, 会将新签发的 作为查询参数构建 路径,并通过 GET 请求重定向浏览器至该路径。因此,该令牌会出现在请求行中,而 Web 服务器、反向代理、请求遥测系统以及浏览器自身的历史记录都会记录该令牌。这些日志和
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| team-alembic | ash_authentication_phoenix | 1.7.0 ~ 2.17.4 |
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication_phoenix | 903f3a386e1aba2f7b070187ef6f31215a92bdfd ~ * |
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | 3.10.5 ~ 4.15.0 |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 ~ * |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-82761 | 9.1 CRITICAL | AshAuthentication 令牌重放竞态漏洞 |
| CVE-2026-86533 | 9.1 CRITICAL | AshAuthentication Phoenix已吊销会话接收漏洞 |
| CVE-2026-85500 | 9.1 CRITICAL | Ash Authentication require_confirmed_with未强制校验漏洞 |
| CVE-2026-88952 | 9.1 CRITICAL | AshAuthentication OAuth2 账户链接逻辑缺陷 |
| CVE-2026-91039 | 9.1 CRITICAL | ash_authentication 动态 OIDC 跨连接账户接管漏洞 |
| CVE-2026-82760 | 8.2 HIGH | AshAuthentication API 密钥登录资源耗尽漏洞 |
| CVE-2026-82685 | 7.6 HIGH | AshAuthentication 确认令牌通用漏洞 |
| CVE-2026-80218 | 7.6 HIGH | AshAuthentication 登录令牌跨资源复用漏洞 |
| CVE-2026-78223 | 6.9 MEDIUM | AshAuthentication 凭据撤销记录 JWT 验证漏洞 |
| CVE-2026-86522 | 6.3 MEDIUM | AshAuthentication 日志注入漏洞 |
| CVE-2026-81637 | 2.3 LOW | AshAuthentication 2.0.0 重放式CSRF漏洞 |
| CVE-2026-82723 | 1.8 LOW | AshAuthentication 审计日志记录密码摘要 |
| CVE-2026-82759 | 1.8 LOW | AshAuthentication审计日志哈希模式IP脱敏可逆漏洞 |
暂无评论