MEDIUM✓ PATCH🇬🇧 English

CVE-2026-3255

CVSS 6.5v3.1pub. 2026-02-27upd. 2026-03-04

Wersje HTTP::Session2 poniżej 1.12 dla Perl mogą generować słabe identyfikatory sesji przy użyciu funkcji rand(). Generator identyfikatora sesji HTTP::Session2 zwraca hash SHA-1 inicjowany wbudowaną funkcją rand(), czasem epoki i PID-em. PID pochodzi z małego zakresu numerów, a czas epoki można zgadnąć, jeśli nie wycieknie z nagłówka HTTP Date. Wbudowana funkcja rand() jest nieodpowiednia do zastosowań kryptograficznych. HTTP::Session2 w wersji 1.02 i nowszych próbuje użyć urządzenia /dev/urandom do generowania identyfikatora sesji, ale jeśli urządzenie jest niedostępne (na przykład w Windows), wraca do opisanej wyżej niezabezpieczonej metody.

Pokaż oryginał (EN)

HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand() function is unsuitable for cryptographic usage. HTTP::Session2 after version 1.02 will attempt to use the /dev/urandom device to generate a session id, but if the device is unavailable (for example, under Windows), then it will revert to the insecure method described above.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
  • Tokuhirom Http\

    APP
    Tokuhirom
    \
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2018-25160MEDIUM6.5ten sam produkt

HTTP::Session2 w wersji 1.09 i wcześniejszych dla Perla nie waliduje formatu identyfikatorów sesji dostarczony...

CVE-2025-15604CRITICAL9.8PL ✓ten sam vendor

Amon2 dla Perl — słabe generowanie losowości w funkcjach bezpieczeństwa

CVE-2026-3257CRITICAL9.8PL ✓ten sam vendor

UnQLite dla Perl — osadzona nieaktualna biblioteka z potencjalnym heap overflow

CVE-2026-5082MEDIUM5.3ten sam vendor

Amon2::Plugin::Web::CSRFDefender w wersjach od 7.00 do 7.03 dla Perla generuje niezabezpieczony identyfikator ...