Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2404 | Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated. |
Github GHSA |
GHSA-3cjh-p6pw-jhv9 | Pow Mnesia cache doesn't invalidate all expired keys on startup |
Tue, 24 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-24T18:11:16.178Z
Reserved: 2023-09-08T20:57:45.572Z
Link: CVE-2023-42446
Updated: 2024-08-02T19:23:38.521Z
Status : Modified
Published: 2023-09-18T22:15:47.247
Modified: 2024-11-21T08:22:32.813
Link: CVE-2023-42446
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA