Insufficient Session Expiration vulnerability in ash-project ashauthenticationphoenix allows Session Hijacking. This vulnerability is associated with program files lib/ashauthenticationphoenix/controller.ex.
This issue affects ashauthenticationphoenix until 2.10.0.
{
"cna_assigner": "EEF",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4754.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "de3ecd611fb0f3b3f9f861f9397c2a5e97f5f4d2"
},
{
"fixed": "a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-613"
]
}