CVE-2020-5205
09.01.2020, 02:15
In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
powauth | pow | 𝑥 < 1.0.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References