CVE-2017-1000053

EUVD-2022-1640
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
plug_projectplug
1.0.0 ≤
𝑥
< 1.0.4
plug_projectplug
1.1.0 ≤
𝑥
< 1.1.7
plug_projectplug
1.2.0 ≤
𝑥
< 1.2.3
plug_projectplug
1.3.0 ≤
𝑥
< 1.3.2
𝑥
= Vulnerable software versions