ash_admin is vulnerable to Session Hijacking
83
High Risk
AshAdmin's browser client reads session cookies with an unanchored regular expression built from the cookie name, so any cookie whose name merely ends with the requested name also matches. A cookie set on a sibling subdomain under a shared parent domain can shadow the real actor, tenant, or authorization cookies that drive the LiveView connection. This lets externally supplied cookie values rebind the admin session to a different actor resource, tenant, or authorization mode. The fix matches admin session cookies by exact name.
You are affected if you are using a version that falls within the vulnerable range and your AshAdmin dashboard is served on a domain that shares a parent domain with a host that can set cookies your application does not control.
ash_admin is vulnerable to Session Hijacking in versions 0.9.1 - 1.3.0.
Upgrade the ash_admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.