CVE-2017-1000053

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
plug_projectplug
1.0.0 ≤
𝑥
< 1.0.4
plug_projectplug
1.1.0 ≤
𝑥
< 1.1.7
plug_projectplug
1.2.0 ≤
𝑥
< 1.2.3
plug_projectplug
1.3.0 ≤
𝑥
< 1.3.2
𝑥
= Vulnerable software versions