CVE-2017-1000052

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
17/07/2017
Last modified:
20/04/2025

Description

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plug_project:plug:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.4 (excluding)
cpe:2.3:a:plug_project:plug:*:*:*:*:*:*:*:* 1.1.0 (including) 1.1.7 (excluding)
cpe:2.3:a:plug_project:plug:*:*:*:*:*:*:*:* 1.2.0 (including) 1.2.3 (excluding)
cpe:2.3:a:plug_project:plug:*:*:*:*:*:*:*:* 1.3.0 (including) 1.3.2 (excluding)