{"id":"GHSA-4r2f-6fm9-2qgh","summary":"Duplicate Advisory: Ecto lacks a protection mechanism","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2xxx-fhc8-9qvq. This link is maintained to preserve external references.\n\n## Original Description\nEcto 2.2.0 lacks a certain protection mechanism associated with the interaction between `is_nil` and `raise`.","modified":"2026-09-10T03:49:56.638032084Z","published":"2023-01-10T06:30:25Z","withdrawn":"2026-01-22T20:38:52Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-01-10T22:16:53Z","nvd_published_at":"2023-01-10T06:15:00Z","cwe_ids":[]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20166"},{"type":"WEB","url":"https://github.com/elixir-ecto/ecto/pull/2125"},{"type":"WEB","url":"https://github.com/elixir-ecto/ecto/commit/db55b0cba6525c24ebddc88ef9ae0c1c00620250"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xxx-fhc8-9qvq"},{"type":"PACKAGE","url":"https://github.com/elixir-ecto/ecto"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/elixir-ecto/0m4NPfg_MMU"}],"affected":[{"package":{"name":"ecto","ecosystem":"Hex","purl":"pkg:hex/ecto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.2.1"}]}],"versions":["2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-4r2f-6fm9-2qgh/GHSA-4r2f-6fm9-2qgh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}