CVE-2023-42446

    Dashboard / Vulnerabilities / CVE-2023-42446

    CVE-2023-42446

    Published: 18 Sept 2023Last Modified: 12 Aug 2026

    Summary: Pow Mnesia cache doesn't invalidate all expired keys on startup

    Details: Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A session may expire when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than a session's remaining TTL. Version 1.0.34 contains a patch for this issue. As a workaround, expired keys, including all expired sessions, can be manually invalidated.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 521e5d420e1f00d4b9bf1667af5046a376d72c5b

    Affected versions

    v1.0.33
    v1.0.32
    v1.0.31
    v1.0.30
    v1.0.29
    v1.0.28
    v1.0.27
    v1.0.26
    v1.0.25
    v1.0.24
    v1.0.23
    v1.0.22
    v1.0.21
    v1.0.20
    v1.0.19
    v1.0.18
    v1.0.17
    v1.0.16
    v1.0.15
    v1.0.14

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-42446 | CVE-DB