CVE-2017-1000053
Arbitrary Code Execution in Cookie Serialization
8.1
HIGH
CVSS 3.1
EPSS 1.9%
Description
The default serialization used by Plug session may result in code execution in certain situations. Keep in mind, however, the session cookie is signed and this attack can only be exploited if the attacker has access to your secret key as well as your signing/encryption salts. We recommend users to change their secret key base and salts if they suspect they have been leaked, regardless of this vulnerability.
How to fix CVE-2017-1000053
To remediate CVE-2017-1000053, upgrade the affected package to a fixed version below.
- —upgrade to 1.0.4 or later
Is CVE-2017-1000053 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.0.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |