CVE-2017-1000052
—CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
Description
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
- Vendors
- plug project
- Products
- plug
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.