There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version 1.0.0. The vulnerability has been patched in version 1.0.0 and all users should upgrade to this version immediately. Note that this patched version uses a dependency that requires an Elixir version >=1.5.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-09-01T16:30:14
Updated: 2024-08-04T13:08:22.305Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15150
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-09-01T17:15:11.840
Modified: 2020-09-11T14:34:02.573
Link: CVE-2020-15150
Redhat
No data.