RSS   Vulnerabilities for 'PLUG'   RSS

2017-07-17
 
CVE-2017-1000053

 

 
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

 
 
CVE-2017-1000052

CWE-74
 

 
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.

 


Copyright 2024, cxsecurity.com

 

Back to Top