PT-2020-14228 · Elixir · Paginator
Peter Stöckli
·
Published
2020-09-01
·
Updated
2022-04-12
·
CVE-2020-15150
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Paginator versions prior to 1.0.0
Description
The issue allows for Remote Code Execution (RCE) attacks via input parameters to the
paginate() function. This potentially affects all current users of Paginator prior to version 1.0.0.Recommendations
For versions prior to 1.0.0, upgrade to version 1.0.0 immediately, ensuring your Elixir version is >=1.5 to accommodate the dependency requirements of the patched version. As a temporary workaround, consider restricting input parameters to the
paginate() function until the upgrade is possible.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paginator