CVE-2018-1000883
Last modified
CVE-2018-1000883 is a vulnerability of currently unknown severity. Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plug Project | Plug | > 1.0.6, <= 1.1.9 |
| Plug Project | Plug | > 1.1.9, <= 1.2.5 |
| Plug Project | Plug | >= 1.2.5, < 1.3.5 |
| Plug Project | Plug | >= 1.3.5 |
References
- https://github.com/elixir-plug/plug/commit/8857f8ab4acf9b9c22e80480dae2636692f5f573Patch, Third Party Advisory
- https://github.com/elixir-plug/plug/commit/8857f8ab4acf9b9c22e80480dae2636692f5f573Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000883?
How severe is CVE-2018-1000883?
How do I fix CVE-2018-1000883?
Are you affected by CVE-2018-1000883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
