coherence
A full featured, configurable authentication and user management system for Phoenix.
Activity
- Latest release
- 2y ago
- Total releases
- 12
- Cadence
- ~28 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jul 11, 2016
| Version | Released | |
|---|---|---|
0.8.0
minor
|
0.8.0
minor
Dependencies (11)
+ 3 more |
|
0.5.2
patch
|
0.5.2
patch
Dependencies (9)
+ 1 more |
|
0.5.1
patch
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.5.1
patch
Dependencies (9)
+ 1 more |
|
0.5.0
minor
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.5.0
minor
Dependencies (9)
+ 1 more |
|
0.4.0
minor
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.4.0
minor
Dependencies (9)
+ 1 more |
|
0.3.1
patch
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.3.1
patch
Dependencies (9)
+ 1 more |
|
0.3.0
minor
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.3.0
minor
Dependencies (9)
+ 1 more |
|
0.2.0
minor
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.2.0
minor
Dependencies (9)
+ 1 more |
|
0.1.3
patch
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.1.3
patch
Dependencies (9)
+ 1 more |
|
0.1.2
patch
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.1.2
patch
Dependencies (9)
+ 1 more |
|
0.1.1
patch
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.1.1
patch
Dependencies (9)
+ 1 more |
|
0.1.0
initial
1 CVE
CVE-2018-20301
GHSA-mrq8-53r4-3j5m
Feb 10, 2022
Permissive parameters and privilege escalation
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request. Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.3.0
0.3.1
0.4.0
0.5.0
0.5.1
Fixed in
0.5.2
References Updated Dec 10, 2025 · Source: OSV.dev |
0.1.0
initial
Dependencies (9)
+ 1 more |