Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-10007

Опубликовано: 09 июн. 2026
Источник: debian

Описание

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcatalyst-plugin-authentication-perlunfixedpackage
libcatalyst-plugin-authentication-perlno-dsatrixiepackage
libcatalyst-plugin-authentication-perlpostponedbookwormpackage
libcatalyst-plugin-authentication-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/40832427/

  • Fixed by: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b1385ea87a2491b64f33169222af19982d0acce3 (v0.10_027)

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

CVSS3: 9.1
nvd
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

CVSS3: 9.1
github
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.