THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-4754 — Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller on

[NVD] CVE-2025-4754 — Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards. The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller on

lownvdPublished 2025-06-17

CVE-2025-4754 CVSS: None Published: 2025-06-17T15:15:53.273

Insufficient Session Expiration vulnerability in team-alembic ash_authentication_phoenix allows a session token captured before sign-out to remain usable afterwards.

The default sign_out/2 that AshAuthentication.Phoenix.Controller injects into an application's auth controller only calls Plug.Conn.clear_session/1. It never revokes the s

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-4754