GHSA-v2wf-c3j6-wpvw
Session fixation
Quick fix
GHSA-v2wf-c3j6-wpvw — pow: upgrade to the fixed version with the command below.
mix deps.update powDetails
### Impact
The use of `Plug.Session` in `Pow.Plug.Session` is susceptible to session fixation attacks if a persistent session store is used for `Plug.Session`, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.
### Workarounds
Call `Plug.Conn.configure_session(conn, renew: true)` periodically and after privilege change. A custom authorization plug can be written where the `create/3` method should return the `conn` only after `Plug.Conn.configure_session/2` have been called on it.
### References https://github.com/danschultzer/pow/commit/578ffd3d8bb8e8a26077b644222186b108da474f https://www.owasp.org/index.php/Session_fixation
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/danschultzer/pow/security/advisories/GHSA-v2wf-c3j6-wpvw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-5205[ADVISORY]
- https://github.com/danschultzer/pow/commit/578ffd3d8bb8e8a26077b644222186b108da474f[WEB]
- https://github.com/danschultzer/pow[PACKAGE]
- https://github.com/danschultzer/pow/blob/master/CHANGELOG.md#v1016-2020-01-07[WEB]