PT-2025-18947 · Unknown+1 · Mojolicious+1
Antoine Cervoise
+2
·
Published
2025-05-03
·
Updated
2025-10-20
·
CVE-2024-58134
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mojolicious versions 0.999922 through 9.39
Description
The issue concerns the use of a hard-coded string or the application's class name as a HMAC session secret by default in Mojolicious for Perl. This predictable default secret can be exploited to forge session cookies, allowing an attacker to tamper with or hijack another user's session if they know or guess the secret.
Recommendations
For Mojolicious versions 0.999922 through 9.39, consider changing the default HMAC session secret to a unique, randomly generated value to prevent session cookie forgery. As a temporary workaround, restrict access to sensitive user sessions until a secure secret can be implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Mojolicious