PT-2025-18947 · Unknown+1 · Mojolicious+1

Antoine Cervoise

+2

·

Published

2025-05-03

·

Updated

2025-10-20

·

CVE-2024-58134

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mojolicious versions 0.999922 through 9.39
Description The issue concerns the use of a hard-coded string or the application's class name as a HMAC session secret by default in Mojolicious for Perl. This predictable default secret can be exploited to forge session cookies, allowing an attacker to tamper with or hijack another user's session if they know or guess the secret.
Recommendations For Mojolicious versions 0.999922 through 9.39, consider changing the default HMAC session secret to a unique, randomly generated value to prevent session cookie forgery. As a temporary workaround, restrict access to sensitive user sessions until a secure secret can be implemented.

Exploit

Fix

Weakness Enumeration

Related Identifiers

AZL-61673
AZL-61825
CVE-2024-58134

Affected Products

Debian
Mojolicious