CVE-2017-1000053

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
plug_projectplug
1.0.0 ≤
𝑥
< 1.0.4
plug_projectplug
1.1.0 ≤
𝑥
< 1.1.7
plug_projectplug
1.2.0 ≤
𝑥
< 1.2.3
plug_projectplug
1.3.0 ≤
𝑥
< 1.3.2
𝑥
= Vulnerable software versions