Powauth develops a focused mobile and web authentication platform centered on products such as Pow and Powassent, with its vulnerability disclosures clustering around certificate validation, session management, and resource-consumption issues. The durable signal reflects the authentication-layer role of these products and their exposure to weaknesses including improper certificate-expiration handling, session fixation, and uncontrolled resource consumption. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powauth over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42446MEDIUM Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` | Sep 18, 2023 | 6.5 | 20 | NO | NO |
CVE-2019-16764MEDIUM The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.AuthorizationController` a value is fetched from the user provided par | Nov 25, 2019 | 5.5 | 18 | NO | NO |
CVE-2020-5205MEDIUM In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, s | Jan 9, 2020 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powauth.
Media articles that mention a CVE ID that affects a product developed by Powauth — matched by CVE ID, not by vendor name.