CVE-2018-1000883
20.12.2018, 21:29
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.Enginsight
Vendor | Product | Version |
---|---|---|
plug_project | plug | 1.0.6 < 𝑥 ≤ 1.1.9 |
plug_project | plug | 1.1.9 < 𝑥 ≤ 1.2.5 |
plug_project | plug | 1.2.5 ≤ 𝑥 < 1.3.5 |
plug_project | plug | 1.3.5 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References