We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex. This issue affects ash_authentication_phoenix until 2.10.0.
Reserved 2025-05-15 | Published 2025-06-17 | Updated 2025-06-17 | Assigner EEFCWE-613 Insufficient Session Expiration
James Harton
Zach Daniel
Mike Buhot
Jonatan Männchen
Josh Price
github.com/...hoenix/security/advisories/GHSA-f7gq-h8jv-h3cq
github.com/team-alembic/ash_authentication_phoenix/pull/634
Support options