{"id":"CVE-2017-20166","details":"Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.","aliases":["GHSA-2xxx-fhc8-9qvq"],"modified":"2026-08-07T14:49:08.806173Z","published":"2023-01-10T06:15:09.610Z","references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/elixir-ecto/0m4NPfg_MMU"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xxx-fhc8-9qvq"},{"type":"FIX","url":"https://github.com/elixir-ecto/ecto/commit/db55b0cba6525c24ebddc88ef9ae0c1c00620250"},{"type":"EVIDENCE","url":"https://github.com/elixir-ecto/ecto/pull/2125"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elixir-ecto/ecto","events":[{"introduced":"4f84ddfbc89f83d6eed8362bf24e77bec5dcf81e"},{"last_affected":"4f84ddfbc89f83d6eed8362bf24e77bec5dcf81e"},{"fixed":"db55b0cba6525c24ebddc88ef9ae0c1c00620250"}],"database_specific":{"cpe":"cpe:2.3:a:ecto_project:ecto:2.2.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.2.0"},{"last_affected":"2.2.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.2.0","v2.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20166.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}