GHSA-5v4m-c73v-c7gq
Dashboard / Vulnerabilities / GHSA-5v4m-c73v-c7gq
Summary: Arbitrary Code Execution in Cookie Serialization
Details: The default serialization used by Plug session may result in code execution in certain situations. Keep in mind, however, the session cookie is signed and this attack can only be exploited if the attacker has access to your secret key as well as your signing/encryption salts. We recommend users to change their secret key base and salts if they suspect they have been leaked, regardless of this vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-1000053, https://elixirforum.com/t/security-releases-for-plug/3913, https://github.com/elixir-plug/plug
Affected packages
Package
Name: plug
Purl: pkg:hex/plug
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.0.4
Affected versions
0.10.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
