Plug Project / Plug
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-1000883 | Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack… | MEDIUM | 6.5 | Dec 20, 2018 |
| CVE-2017-1000053 | Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session. | HIGH | 8.1 | Jul 13, 2017 |
| CVE-2017-1000052 | Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetyp… | HIGH | 7.8 | Jul 13, 2017 |
Showing 1 to 3 of 3 CVEs