Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Powauth Subscribe
Filtered by product Pow
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5205 1 Powauth 1 Pow 2020-01-17 5.5 MEDIUM 5.4 MEDIUM
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.