HomeDefault status
unaffected
2.10 (custom)
affected
Description
Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.
Problem types
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Product status
2.10 (custom)
Credits
Robert Rothenberg
References
metacpan.org/dist/Maypole/source/lib/Maypole/Session.pm