PT-2025-38638 · Starch · Starch
Published
2025-09-20
·
Updated
2025-09-21
·
CVE-2025-40925
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Starch versions 0.14 and earlier
Description
Starch generates session IDs insecurely. The default session ID generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in
rand function, the PID, and internal Perl reference addresses. The PID will come from a small set of numbers, and the epoch time may be guessed. The rand function is unsuitable for cryptographic usage. Predictable session IDs could allow an attacker to gain access to systems.Recommendations
Update Starch to a version later than 0.14.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Starch