PT-2025-29908 · Catalyst+1 · Catalyst-Plugin-Session+1

CVE-2025-40924

·

Published

2025-01-01

·

Updated

2025-07-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Catalyst::Plugin::Session versions prior to 0.44
Description The session ID generation process uses low-entropy data, including a counter, epoch time, the rand function, the process ID (PID), and the Catalyst context. The rand function is unsuitable for cryptographic purposes. Predictable session IDs could allow an attacker to gain unauthorized access to systems.
Recommendations Update to Catalyst::Plugin::Session version 0.44 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40924

Affected Products

Catalyst-Plugin-Session
Debian