{"id":"CVE-2025-4754","title":"Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.\n\nThe default sign_out/2 that AshAuthentication.Phoenix.Controller injec…","summary":"Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.\n\nThe default sign_out/2 that AshAuthentication.Phoenix.Controller injec…","severity":"low","cvss":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-613"],"vendor":"team-alembic","product":"ash_authentication_phoenix","affected":["ash_authentication_phoenix >= 0.1.0 < 2.10.0","team-alembic/ash_authentication_phoenix >= 05ab4f438bf0cd0fdfb279d912bbe0d2c3620e02 < a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"],"published":"2025-06-17","updated":"2026-09-22","sourceUpdated":"2026-09-22T10:17:08.407","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-4754","references":[{"url":"https://cna.erlef.org/cves/CVE-2025-4754.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/05ab4f438bf0cd0fdfb279d912bbe0d2c3620e02","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication_phoenix/pull/634","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-f7gq-h8jv-h3cq","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2025-4754","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"tags":["nvd","cve.org"],"epss":0.0046,"epssPercentile":0.39008,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-06-17T14:40:37.216297Z"},"cvssSource":"cna","ingestedAt":"2026-07-24T15:30:57.747Z","slug":"CVE-2025-4754","body":"## Overview\n\nInsufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.\n\nThe default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It never revokes the stored session or bearer tokens, so a token obtained before sign-out, through script injection, interception or device theft, keeps authenticating until its own expiry. Changing the password still revokes it.\n\nThis issue affects ash_authentication_phoenix: from 0.1.0 before 2.10.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":13,"depthScoreParts":{"impact":12.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":209000,"id":"CVE-2025-4754","ts":1790071338420,"field":"cvss","old":null,"new":"2.3"},{"seq":208999,"id":"CVE-2025-4754","ts":1790071338420,"field":"severity","old":"none","new":"low"}]}