Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plack
Plack plack-middleware-session |
|
| CPEs | cpe:2.3:a:plack:plack-middleware-session:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plack
Plack plack-middleware-session |
Thu, 11 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plack Project
Plack Project plack |
|
| Vendors & Products |
Plack Project
Plack Project plack |
Tue, 09 Dec 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks | |
| Title | Plack::Middleware::Session versions before 0.17 for Perl may be vulnerable to HMAC comparison timing attacks | |
| Weaknesses | CWE-1254 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-12-11T14:36:31.485Z
Reserved: 2025-07-10T09:30:45.910Z
Link: CVE-2013-10031
Updated: 2025-12-09T19:53:05.460Z
Status : Analyzed
Published: 2025-12-09T01:16:42.587
Modified: 2025-12-16T19:16:16.547
Link: CVE-2013-10031
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:30Z