Header Injection
Moderate severity
GitHub Reviewed
Published
Apr 12, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Package
Affected versions
< 1.0.6
>= 1.1.0, < 1.1.9
>= 1.2.0, < 1.2.5
>= 1.3.0, < 1.3.5
Patched versions
1.0.6
1.1.9
1.2.5
1.3.5
Description
Published to the GitHub Advisory Database
Apr 12, 2022
Reviewed
Apr 12, 2022
Last updated
Jan 11, 2023
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.
References