Plack-Middleware-Session
Middleware for session management
Security Advisories for Plack-Middleware-Session in cpan
about 1 year ago
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of nu...
cpan
Plack-Middleware-Session
Critical
almost 12 years ago
Plack::Middleware::Session::Cookie 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server, when the middleware is enabled without a secret.
cpan
Plack-Middleware-Session