CPANSA-Plack-Middleware-Session-2014-125112: Plack-Middleware-Session vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-03-26T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-03-26T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.
Vulnerabilities
CVE-2014-125112
Vulnerability DescriptionPlack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution.
Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.
| Weakness | CWE-565 : Reliance on Cookies without Validation and Integrity Checking |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Plack-Middleware-Session less than 0.21 |
|
Fixed
- Plack-Middleware-Session greater than or equal 0.21
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Plack-Middleware-Session-2014-125112 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-plack-middleware-session-2014-125112.json - https://gist.github.com/miyagawa/2b8764af908a0dacd43d external
https://gist.github.com/miyagawa/2b8764af908a0dacd43d - https://metacpan.org/release/MIYAGAWA/Plack-Middleware-Session-0.23-TRIAL/changes external
https://metacpan.org/release/MIYAGAWA/Plack-Middleware-Session-0.23-TRIAL/changes - http://www.openwall.com/lists/oss-security/2026/03/26/2 external
http://www.openwall.com/lists/oss-security/2026/03/26/2 - CVE-2014-125112 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2014-125112
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Thu Mar 26 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/