{"id":"CVE-2025-40924","summary":"Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely","details":"Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely.\n\nThe session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Catalyst context. This information is of low entropy. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.\n\nPredicable session ids could allow an attacker to gain access to systems.","modified":"2026-08-12T03:51:35.611005744Z","published":"2025-07-17T13:33:43.739Z","database_specific":{"cwe_ids":["CWE-338","CWE-340"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40924.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://metacpan.org/release/HAARG/Catalyst-Plugin-Session-0.43/source/lib/Catalyst/Plugin/Session.pm#L632"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40924.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40924"},{"type":"REPORT","url":"https://github.com/perl-catalyst/Catalyst-Plugin-Session/pull/5"},{"type":"FIX","url":"https://github.com/perl-catalyst/Catalyst-Plugin-Session/commit/c0e2b4ab1e42ebce1008286db8c571b6ee98c22c.patch"},{"type":"PACKAGE","url":"https://github.com/perl-catalyst/Catalyst-Plugin-Session"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/perl-catalyst/catalyst-plugin-session","events":[{"introduced":"36316211769ad9af45176c6eb59f4cc68ae5ee2d"},{"fixed":"263d0fb88083959c821ef95fe8ab89f49b9c8532"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.01"},{"fixed":"0.44"}]}}],"versions":["v0.43","v0.42","0.41","0.40","0.36","0.35","v0.34","v0.32","v0.31","v0.30","v0.29","v0.28","v0.27","v0.26_01","v0.26","v0.25","v0.24","v0.23","v0.22","v0.21","v0.20","v0.19_01","v0.19","v0.18","v0.17","v0.16","v0.15","v0.13","v0.12","v0.11","v0.09","v0.06","v0.05","v0.04","v0.03","v0.02","v0.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40924.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}