VulnerabilityModified
CVE-2018-1000883
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added.
MEDIUM 6.5EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- plug project/plug
- Source
- cve@mitre.org
References
- https://github.com/dependabot/elixir-security-advisories/blob/master/packages/plug/2017-04-17.ymlThird Party Advisory
- https://github.com/elixir-plug/plug/commit/8857f8ab4acf9b9c22e80480dae2636692f5f573Patch, Third Party Advisory
- https://github.com/dependabot/elixir-security-advisories/blob/master/packages/plug/2017-04-17.ymlThird Party Advisory
- https://github.com/elixir-plug/plug/commit/8857f8ab4acf9b9c22e80480dae2636692f5f573Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.