CVE-2017-1000053: Plug Project Plug
High severity, CVSS 8.1. EPSS: 1.9% chance of exploitation in the next 30 days.
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
Affected products
- Plug Project Plug: from 1.0.0, before 1.0.4 (fixed in 1.0.4); from 1.1.0, before 1.1.7 (fixed in 1.1.7); from 1.2.0, before 1.2.3 (fixed in 1.2.3); from 1.3.0, before 1.3.2 (fixed in 1.3.2)
Published 2017-07-17. Last modified 2026-06-17.