CVE-2017-1000052

HIGH

Elixir Plug <v1.0.4,v1.1.7,v1.2.3,v1.3.2 - Code Injection

Title source: llm
STIX 2.1

Description

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
https://elixirforum.com/t/security-releases-for-plug/3913

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 33.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (2)
Hex/plug 0 - 1.0.4Hex
plug_project/plug 1.0.0 - 1.0.4
Published Jul 17, 2017
Tracked Since Feb 18, 2026