Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w98m-2xqg-9cvj

Опубликовано: 12 апр. 2022
Источник: github
Github: Прошло ревью

Описание

Remote Code Execution in paginator

There is a vulnerability in Paginator which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function.

Impact

There is a vulnerability in Paginator which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version >= 1.0.0.

Patches

The vulnerability has been patched in version 1.0.0 and all users should upgrade to this version immediately. Note that this patched version uses a dependency that requires an Elixir version >=1.5.

Credits

Thank you to Peter Stöckli.

Пакеты

Наименование

paginator

Затронутые версииВерсия исправления

< 1.0.0

1.0.0

EPSS

Процентиль: 90%
0.05345
Низкий

Связанные уязвимости

CVSS3: 9
nvd
больше 5 лет назад

There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version 1.0.0. The vulnerability has been patched in version 1.0.0 and all users should upgrade to this version immediately. Note that this patched version uses a dependency that requires an Elixir version >=1.5.

EPSS

Процентиль: 90%
0.05345
Низкий