eef-cve-2025-4754

CVSS 2.3 osv_hex
Description

## Summary Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default `sign_out/2` that `AshAuthentication.Phoenix.Controller` injects into an application's auth controller only calls `Plug.Conn.clear_session/1`. It never revokes the stored session or bearer tokens, so a token obtained before sign-out, through script injection, interception or device theft, keeps authenticating until its own expiry. Changing the password still revokes it. This issue affects ash_authentication_phoenix: from 0.1.0 before 2.10.0.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://cna.erlef.org/osv/EEF-CVE-2025-4754.json"
      },
      "package": {
        "ecosystem": "Hex",
        "name": "ash_authentication_phoenix",
        "purl": "pkg:hex/ash_authentication_phoenix"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.1.0"
            },
            {
              "fixed": "2.10.0"
            }
          ],
          "type": "SEMVER"
        }
      ],
      "versions": [
        "1.0.0",
        "1.0.1",
        "1.1.0",
        "1.2.0",
        "1.3.0",
        "1.3.1",
        "1.4.0",
        "1.4.1",
        "1.4.2",
        "1.4.3",
        "1.4.4",
        "1.4.5",
        "1.4.6",
        "1.4.7",
        "1.4.8",
        "1.5.0",
        "1.5.1",
        "1.6.0",
        "1.6.1",
        "1.6.2",
        "1.6.3",
        "1.6.4",
        "1.6.5",
        "1.6.6",
        "1.7.0",
        "1.7.1",
        "1.7.2",
        "1.7.3",
        "1.8.0",
        "1.8.1",
        "1.8.2",
        "1.8.3",
        "1.8.4",
        "1.8.5",
        "1.8.6",
        "1.8.7",
        "1.9.0",
        "1.9.1",
        "1.9.2",
        "1.9.3",
        "1.9.4",
        "2.0.0",
        "2.0.0-rc.0",
        "2.0.0-rc.1",
        "2.0.0-rc.2",
        "2.0.1",
        "2.0.2",
        "2.1.0",
        "2.1.1",
        "2.1.10",
        "2.1.11",
        "2.1.2",
        "2.1.3",
        "2.1.4",
        "2.1.5",
        "2.1.6",
        "2.1.7",
        "2.1.8",
        "2.1.9",
        "2.2.0",
        "2.2.1",
        "2.3.0",
        "2.4.0",
        "2.4.1",
        "2.4.2",
        "2.4.3",
        "2.4.4",
        "2.4.5",
        "2.4.6",
        "2.4.7",
        "2.4.8",
        "2.5.0",
        "2.5.1",
        "2.5.2",
        "2.5.3",
        "2.5.4",
        "2.6.0",
        "2.6.1",
        "2.6.2",
        "2.6.3",
        "2.7.0",
        "2.8.0",
        "2.9.0"
      ]
    },
    {
      "database_specific": {
        "source": "https://cna.erlef.org/osv/EEF-CVE-2025-4754.json"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "05ab4f438bf0cd0fdfb279d912bbe0d2c3620e02"
            },
            {
              "fixed": "a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"
            }
          ],
          "repo": "https://github.com/team-alembic/ash_authentication_phoenix",
          "type": "GIT"
        }
      ],
      "versions": [
        "v2.9.0",
        "v2.7.0",
        "v2.6.3",
        "v2.6.2",
        "v2.6.1",
        "v2.6.0",
        "v2.5.4",
        "v2.5.3",
        "v2.5.2",
        "v2.5.1",
        "v2.5.0",
        "v2.4.8",
        "v2.4.7",
        "v2.4.6",
        "v2.4.5",
        "v2.4.4",
        "v2.4.3",
        "v2.4.2",
        "v2.4.1",
        "v2.4.0",
        "v2.3.0",
        "v2.2.1",
        "v2.2.0",
        "v2.1.11",
        "v2.1.10",
        "v2.1.9",
        "v2.1.8",
        "v2.1.7",
        "v2.1.6",
        "v2.1.5",
        "v2.1.4",
        "v2.1.3",
        "v2.1.2",
        "v2.1.1",
        "v2.1.0",
        "v2.0.2",
        "v2.0.1",
        "v2.0.0",
        "v2.0.0-rc.3",
        "v2.0.0-rc.2",
        "v2.0.0-rc.1",
        "v2.0.0-rc.0",
        "v1.9.4",
        "v1.9.2",
        "v1.9.1",
        "v1.9.0",
        "v1.8.7",
        "v1.8.6",
        "v1.8.5",
        "v1.8.4",
        "v1.8.3",
        "v1.8.2",
        "v1.8.1",
        "v1.8.0",
        "v1.7.3",
        "v1.7.2",
        "v1.7.1",
        "v1.7.0",
        "v1.6.6",
        "v1.6.4",
        "v1.6.2",
        "v1.6.1",
        "v1.6.0",
        "v1.5.0",
        "v1.4.8",
        "v1.4.7",
        "v1.4.6",
        "v1.4.5",
        "v1.4.4",
        "v1.4.3",
        "v1.4.2",
        "v1.4.1",
        "v1.4.0",
        "v1.3.1",
        "v1.3.0",
        "v1.2.0",
        "v1.1.0",
        "v1.0.1",
        "v1.0.0",
        "v0.5.0",
        "v0.4.0",
        "v0.3.0",
        "v0.2.0",
        "v0.1.0"
      ]
    }
  ],
  "aliases": [
    "CVE-2025-4754",
    "GHSA-f7gq-h8jv-h3cq"
  ],
  "credits": [
    {
      "name": "James Harton",
      "type": "REMEDIATION_REVIEWER"
    },
    {
      "name": "Zach Daniel",
      "type": "REMEDIATION_DEVELOPER"
    },
    {
      "name": "Mike Buhot",
      "type": "ANALYST"
    },
    {
      "name": "Jonatan Männchen / EEF",
      "type": "ANALYST"
    },
    {
      "name": "Josh Price / Alembic",
      "type": "ANALYST"
    }
  ],
  "database_specific": {
    "capec_ids": [
      "CAPEC-593"
    ],
    "cpe_ids": [
      "cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*"
    ],
    "cwe_ids": [
      "CWE-613"
    ]
  },
  "details": "## Summary\n\nInsufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.\n\nThe default `sign_out/2` that `AshAuthentication.Phoenix.Controller` injects into an application's auth controller only calls `Plug.Conn.clear_session/1`. It never revokes the stored session or bearer tokens, so a token obtained before sign-out, through script injection, interception or device theft, keeps authenticating until its own expiry. Changing the password still revokes it.\n\nThis issue affects ash_authentication_phoenix: from 0.1.0 before 2.10.0.",
  "id": "EEF-CVE-2025-4754",
  "modified": "2026-09-22T09:30:03.466444123Z",
  "published": "2025-06-17T14:31:37.006Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-f7gq-h8jv-h3cq"
    },
    {
      "type": "WEB",
      "url": "https://cna.erlef.org/cves/CVE-2025-4754.html"
    },
    {
      "type": "FIX",
      "url": "https://github.com/team-alembic/ash_authentication_phoenix/pull/634"
    },
    {
      "type": "WEB",
      "url": "https://github.com/team-alembic/ash_authentication_phoenix/commit/05ab4f438bf0cd0fdfb279d912bbe0d2c3620e02"
    },
    {
      "type": "FIX",
      "url": "https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"
    },
    {
      "type": "PACKAGE",
      "url": "https://hex.pm/packages/ash_authentication_phoenix"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Missing Session Revocation on Logout in ash_authentication_phoenix"
}
View JSON API Download JSON