Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-10075

Опубликовано: 08 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

A flaw was found in Apache::Session, a Perl module for managing user sessions. This vulnerability allows the session stores, specifically Apache::Session::Store::File and Apache::Session::Store::DB_File, to recreate sessions that were previously deleted. This can lead to the revival of old sessions, potentially with data that was intended to be removed, primarily impacting data integrity.

Отчет

Low impact. This flaw in the Apache::Session Perl module allows for the re-creation of previously deleted sessions. While this primarily affects data integrity by reviving old session records, it does not directly lead to data leakage or modification. Exploitation for authentication bypass is application-dependent and not a direct consequence of the flaw itself.

Меры по смягчению последствий

The vulnerable session store backends (Apache::Session::Store::File and Apache::Session::Store::DB_File) can be replaced with a DBI-based backend such as Apache::Session::Store::DBI, Apache::Session::Store::MySQL, or Apache::Session::Store::Postgres, which are not affected by this flaw. Applications using Apache::Session::Flex can change the Store parameter without other code changes. As an additional defense, applications should validate session contents (e.g. authentication tokens or user attributes) rather than treating session existence alone as proof of authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perlUnder investigation
Red Hat Enterprise Linux 6perlUnder investigation
Red Hat Enterprise Linux 7perlUnder investigation
Red Hat Enterprise Linux 8perlUnder investigation
Red Hat Enterprise Linux 8perl:5.32/perlUnder investigation
Red Hat Enterprise Linux 9perlOut of support scope
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=2467984Apache::Session: Perl: Apache::Session::Store::File: Apache::Session::Store::DB_File: Apache::Session: Information disclosure due to re-creation of deleted sessions

EPSS

Процентиль: 28%
0.00356
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

CVSS3: 9.1
nvd
3 месяца назад

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

CVSS3: 9.1
debian
3 месяца назад

Apache::Session versions through 1.94 for Perl re-creates deleted sess ...

CVSS3: 9.1
github
3 месяца назад

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

EPSS

Процентиль: 28%
0.00356
Низкий

5.3 Medium

CVSS3