PT-2024-3925 · Unknown+2 · Mojolicious+2

Robrwo

·

Published

2024-04-07

·

Updated

2025-04-11

·

CVE-2020-36829

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mojolicious module versions 1.74 through 8.64
Description: The issue is related to a timing attack vulnerability in the secure compare() function of the Mojolicious module for Perl. This vulnerability allows an attacker to manipulate unknown input, leading to a timing discrepancy that can be exploited to guess the length of a secret string. The attacker can act remotely to exploit this issue.
Recommendations: For versions 1.74 through 8.64, update to version 8.65 or later to resolve the issue. As a temporary workaround, consider restricting access to the secure compare() function until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

AZL-43936
AZL-45018
BDU:2024-04335
CVE-2020-36829
DLA-3846-1
OESA-2024-1517
OESA-2024-1518
OESA-2024-1519

Affected Products

Astra Linux
Mojolicious
Red Os