VYPR

by Plug Project

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-1000053Hig0.538.10.01Jul 17, 2017Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
CVE-2017-1000052Hig0.517.80.00Jul 17, 2017Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.