CVE-2025-4754 is an Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix versions prior to 2.10.0, specifically impacting the lib/ash_authentication_phoenix/controller.ex program file. This flaw allows for Session Hijacking, where an attacker could potentially take over a user's active session. The vulnerability has a low CVSS score of 2.3, indicating a network-based attack with low attack complexity and requiring user interaction, resulting in low impact to confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ash-Project | Ash Authentication Phoenix | >= de3ecd611fb0f3b3f9f861f9397c2a5e97f5f4d2, < a3253fb4fc7145aeb403537af1c24d3a8d51ffb1CNA affecteddefault unaffected | |
| Ash-Project | Ash Authentication Phoenix | >= 1.0.0, < 2.10.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.