Home

Description

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

PUBLISHED Reserved 2025-07-10 | Published 2025-12-09 | Updated 2025-12-11 | Assigner CPANSec

Problem types

CWE-1254 Incorrect Comparison Logic Granularity

Product status

Default status
unaffected

0.01 (custom) before 0.17
affected

References

github.com/...ommit/b7f0252269ba1bb812b5dc02303754fe94c808e4 patch

cve.org (CVE-2013-10031)

nvd.nist.gov (CVE-2013-10031)

Download JSON