Critical severity9.8NVD Advisory· Published Jan 10, 2023· Updated Jun 17, 2026
CVE-2017-20166
CVE-2017-20166
Description
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ectoHex | >= 2.2.0, < 2.2.1 | 2.2.1 |
Affected products
2- Ecto/Ectodescription
Patches
Vulnerability mechanics
References
6- github.com/elixir-ecto/ecto/commit/db55b0cba6525c24ebddc88ef9ae0c1c00620250nvdPatchThird Party AdvisoryWEB
- github.com/elixir-ecto/ecto/pull/2125nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2xxx-fhc8-9qvqnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-20166ghsaADVISORY
- groups.google.com/forum/ghsaWEB
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.