在 team-alembic 的 AshAuthentication 和 AshAuthentication.Phoenix 中存在“会话过期机制不足”的漏洞,导致已撤销的会话仍能保持完全认证状态。 具体而言,当资源配置了 且禁用了 时,其会话值会被存储为 的格式。其中包含 是为了支持通过注销操作撤销特定会话。然而,两个读取该会话值的函数—— 和 ——均通过 将值拆分,并丢弃 ,仅将原始的 传递给 以重新加载用户记录。 虽然这两个函数中“令牌存在性”分支会检查令牌,调用 (传入 和 用途),但由于撤销记录从未被读取
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| team-alembic | ash_authentication | 4.9.1 ~ 4.15.0 |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | fcaeb73f76f8f2e9aef8bf637690d2a20dd97596 ~ * |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication_phoenix | 2.10.0 ~ 2.17.4 |
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication_phoenix | a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 ~ * |
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82761 | 9.1 CRITICAL | Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
| CVE-2026-85500 | 9.1 CRITICAL | `require_confirmed_with` is not enforced on the action and fails open on an unreadable att |
| CVE-2026-88952 | 9.1 CRITICAL | OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentic |
| CVE-2026-91039 | 9.1 CRITICAL | dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing c |
| CVE-2026-82760 | 8.2 HIGH | Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in |
| CVE-2026-82685 | 7.6 HIGH | Confirmation token accepted on any record in AshAuthentication |
| CVE-2026-80218 | 7.6 HIGH | Sign-in token minted for one resource accepted by another in AshAuthentication |
| CVE-2026-81632 | 7.2 HIGH | Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix |
| CVE-2026-78223 | 6.9 MEDIUM | Token revocation record built from unverified JWT claims in AshAuthentication |
| CVE-2026-86522 | 6.3 MEDIUM | Log injection via an unescaped password reset identity in AshAuthentication |
| CVE-2026-81637 | 2.3 LOW | Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication |
| CVE-2026-82723 | 1.8 LOW | Actor record with password digest stored in AshAuthentication audit log entries |
| CVE-2026-82759 | 1.8 LOW | Reversible IP address pseudonymisation in AshAuthentication audit log hash mode |
No comments yet