VDB
KO
MEDIUM 6.5

GHSA-9h73-w7ch-rh73

Header Injection

Details

Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex / plug
Introduced in: 0 Fixed in: 1.0.6
Fix mix deps.update plug
Hex / plug
Introduced in: 1.1.0 Fixed in: 1.1.9
Fix mix deps.update plug
Hex / plug
Introduced in: 1.2.0 Fixed in: 1.2.5
Fix mix deps.update plug
Hex / plug
Introduced in: 1.3.0 Fixed in: 1.3.5
Fix mix deps.update plug

References