Insecure deserialization In libplack-middleware-session-perl
Description
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 0.24-1 | ||
debian 14 | 0.24-1 | ||
debian 11 | 0.24-1 | ||
debian 13 | 0.24-1 |
Aliases
1. 2. 3. 4. 5.