Описание
Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
A flaw was found in Apache::Session, a Perl module for managing user sessions. This vulnerability allows the session stores, specifically Apache::Session::Store::File and Apache::Session::Store::DB_File, to recreate sessions that were previously deleted. This can lead to the revival of old sessions, potentially with data that was intended to be removed, primarily impacting data integrity.
Отчет
Low impact. This flaw in the Apache::Session Perl module allows for the re-creation of previously deleted sessions. While this primarily affects data integrity by reviving old session records, it does not directly lead to data leakage or modification. Exploitation for authentication bypass is application-dependent and not a direct consequence of the flaw itself.
Меры по смягчению последствий
The vulnerable session store backends (Apache::Session::Store::File and Apache::Session::Store::DB_File) can be replaced with a DBI-based backend such as Apache::Session::Store::DBI, Apache::Session::Store::MySQL, or Apache::Session::Store::Postgres, which are not affected by this flaw. Applications using Apache::Session::Flex can change the Store parameter without other code changes. As an additional defense, applications should validate session contents (e.g. authentication tokens or user attributes) rather than treating session existence alone as proof of authentication.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | perl | Under investigation | ||
| Red Hat Enterprise Linux 6 | perl | Under investigation | ||
| Red Hat Enterprise Linux 7 | perl | Under investigation | ||
| Red Hat Enterprise Linux 8 | perl | Under investigation | ||
| Red Hat Enterprise Linux 8 | perl:5.32/perl | Under investigation | ||
| Red Hat Enterprise Linux 9 | perl | Out of support scope | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
Apache::Session versions through 1.94 for Perl re-creates deleted sess ...
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
EPSS
5.3 Medium
CVSS3