{"id":"CVE-2020-5205","details":"In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.","aliases":["GHSA-v2wf-c3j6-wpvw"],"modified":"2026-07-09T01:30:13.372583Z","published":"2020-01-09T02:15:13.340Z","references":[{"type":"ADVISORY","url":"https://github.com/danschultzer/pow/blob/master/CHANGELOG.md#v1016-2020-01-07"},{"type":"ADVISORY","url":"https://github.com/danschultzer/pow/security/advisories/GHSA-v2wf-c3j6-wpvw"},{"type":"FIX","url":"https://github.com/danschultzer/pow/commit/578ffd3d8bb8e8a26077b644222186b108da474f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pow-auth/pow","events":[{"introduced":"0"},{"fixed":"4d787349c92a8666ebf6fc72854906fbe79a0526"},{"fixed":"578ffd3d8bb8e8a26077b644222186b108da474f"}],"database_specific":{"cpe":"cpe:2.3:a:powauth:pow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0.16"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.0.15","v1.0.14","v1.0.13","v1.0.12","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5205.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}