Skip to content
Noroxi

plug project records

3 published records for vendor plug project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18

Bar: total · dark part: CISA KEV.

All records

3 records
  • Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Sess

    HighCVSS 8.1No exploitEPSS 2%

    plug project · plugJul 17, 2017

  • Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow user

    HighCVSS 7.8No exploitEPSS 0%

    plug project · plugJul 17, 2017

  • Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be

    MediumCVSS 6.5No exploitEPSS 1%

    plug project · plugDec 20, 2018