Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-125112

Опубликовано: 26 мар. 2026
Источник: debian
EPSS Низкий

Описание

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libplack-middleware-session-perlfixed0.24-1package

Примечания

  • https://gist.github.com/miyagawa/2b8764af908a0dacd43d

  • https://lists.security.metacpan.org/cve-announce/msg/38287006/

  • Version 0.23 changed the warning to error, when secret is not set.

EPSS

Процентиль: 55%
0.0083
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

CVSS3: 9.8
nvd
5 месяцев назад

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

CVSS3: 9.8
github
5 месяцев назад

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

EPSS

Процентиль: 55%
0.0083
Низкий