Описание
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libplack-middleware-session-perl | fixed | 0.21-1 | package |
Примечания
https://lists.security.metacpan.org/cve-announce/msg/35012183/
Fixed by: https://github.com/plack/Plack-Middleware-Session/commit/b7f0252269ba1bb812b5dc02303754fe94c808e4 (0.17)
Связанные уязвимости
CVSS3: 7.5
ubuntu
2 месяца назад
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
CVSS3: 7.5
nvd
2 месяца назад
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
CVSS3: 7.5
github
2 месяца назад
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks