{"id":"GHSA-2xxx-fhc8-9qvq","summary":"Ecto missing `is_nil` requirement","details":"Ecto will not raise on queries with non-explicit nil comparisons (ie if they aren't checked with `is_nil`).","aliases":["CVE-2017-20166"],"modified":"2026-05-14T04:14:20.147802984Z","published":"2022-04-12T19:42:45Z","database_specific":{"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-04-12T19:42:45Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20166"},{"type":"WEB","url":"https://github.com/elixir-ecto/ecto/pull/2125"},{"type":"WEB","url":"https://github.com/elixir-ecto/ecto/commit/db55b0cba6525c24ebddc88ef9ae0c1c00620250"},{"type":"PACKAGE","url":"https://github.com/elixir-ecto/ecto"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/elixir-ecto/0m4NPfg_MMU"}],"affected":[{"package":{"name":"ecto","ecosystem":"Hex","purl":"pkg:hex/ecto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.2.1"}]}],"versions":["2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-2xxx-fhc8-9qvq/GHSA-2xxx-fhc8-9qvq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}