Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfqm-wq4x-p42c

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.

Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.

Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

EPSS

Процентиль: 30%
0.00369
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

CVSS3: 9.1
nvd
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

CVSS3: 9.1
debian
2 месяца назад

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is ...

EPSS

Процентиль: 30%
0.00369
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-384