PT-2020-14228 · Elixir · Paginator

Peter Stöckli

·

Published

2020-09-01

·

Updated

2022-04-12

·

CVE-2020-15150

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Paginator versions prior to 1.0.0
Description The issue allows for Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This potentially affects all current users of Paginator prior to version 1.0.0.
Recommendations For versions prior to 1.0.0, upgrade to version 1.0.0 immediately, ensuring your Elixir version is >=1.5 to accommodate the dependency requirements of the patched version. As a temporary workaround, consider restricting input parameters to the paginate() function until the upgrade is possible.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15150
GHSA-W98M-2XQG-9CVJ

Affected Products

Paginator