Wersje HTTP::Session2 poniżej 1.12 dla Perl mogą generować słabe identyfikatory sesji przy użyciu funkcji rand(). Generator identyfikatora sesji HTTP::Session2 zwraca hash SHA-1 inicjowany wbudowaną funkcją rand(), czasem epoki i PID-em. PID pochodzi z małego zakresu numerów, a czas epoki można zgadnąć, jeśli nie wycieknie z nagłówka HTTP Date. Wbudowana funkcja rand() jest nieodpowiednia do zastosowań kryptograficznych. HTTP::Session2 w wersji 1.02 i nowszych próbuje użyć urządzenia /dev/urandom do generowania identyfikatora sesji, ale jeśli urządzenie jest niedostępne (na przykład w Windows), wraca do opisanej wyżej niezabezpieczonej metody.
▸ Pokaż oryginał (EN)
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand() function is unsuitable for cryptographic usage. HTTP::Session2 after version 1.02 will attempt to use the /dev/urandom device to generate a session id, but if the device is unavailable (for example, under Windows), then it will revert to the insecure method described above.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LTokuhirom Http\
APPTokuhirom\
Powiązane podatności
HTTP::Session2 w wersji 1.09 i wcześniejszych dla Perla nie waliduje formatu identyfikatorów sesji dostarczony...
Amon2 dla Perl — słabe generowanie losowości w funkcjach bezpieczeństwa
UnQLite dla Perl — osadzona nieaktualna biblioteka z potencjalnym heap overflow
Amon2::Plugin::Web::CSRFDefender w wersjach od 7.00 do 7.03 dla Perla generuje niezabezpieczony identyfikator ...