GHSA-3cjh-p6pw-jhv9

    Dashboard / Vulnerabilities / GHSA-3cjh-p6pw-jhv9

    GHSA-3cjh-p6pw-jhv9

    Published: 19 Sept 2023Last Modified: 10 Dec 2025

    Summary: Pow Mnesia cache doesn't invalidate all expired keys on startup

    Details: Use of `Pow.Store.Backend.MnesiaCache` is susceptible to session hijacking as expired keys are not being invalidated correctly on startup. A cache key may become expired when all `Pow.Store.Backend.MnesiaCache` instances have been shut down for a period that is longer than the keys' remaining TTL and the expired key won't be invalidated on startups. ### Workarounds The expired keys, including all expired sessions, can be manually invalidated by running: ```elixir :mnesia.sync_transaction(fn -> Enum.each(:mnesia.dirty_select(Pow.Store.Backend.MnesiaCache, [{{Pow.Store.Backend.MnesiaCache, :_, :_}, [], [:"$_"]}]), fn {_, key, {_value, expire}} -> ttl = expire - :os.system_time(:millisecond) if ttl < 0, do: :mnesia.delete({Pow.Store.Backend.MnesiaCache, key}) end) end) ``` ### References https://github.com/pow-auth/pow/commit/15dc525be03c466daa5d2119ca7acdec7b24ed17 https://github.com/pow-auth/pow/issues/713 https://github.com/pow-auth/pow/pull/714

    Affected packages

    Package

    Name: pow

    Purl: pkg:hex/pow

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.0.14
    Fixed -1.0.34

    Affected versions

    1.0.14
    1.0.15
    1.0.16
    1.0.17
    1.0.18
    1.0.19
    1.0.20
    1.0.21
    1.0.22
    1.0.23
    1.0.24
    1.0.25
    1.0.26
    1.0.27
    1.0.28
    1.0.29
    1.0.30
    1.0.31
    1.0.32
    1.0.33

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3cjh-p6pw-jhv9 | CVE-DB