CVE-2017-1000053

HIGH

Elixir Plug <v1.0.4,v1.1.7,v1.2.3,v1.3.2 - Code Injection

Title source: llm

Description

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

Scores

CVSS v3 8.1
EPSS 0.0115
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status draft

Affected Products (2)

plug_project/plug < 1.0.4
Hex/plug < 1.0.4Hex

Timeline

Published Jul 17, 2017
Tracked Since Feb 18, 2026