← Zurück zur CVE-Suche

CVE-2026-13577

Dancer2

Beschreibung

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the module instance memory address, and a shuffled string of characters (using the List::Util::shuffle function, which also uses the built-in rand function). These are all low-entropy and easily guessed sources. The built-in rand() function is seeded with 32-bits and considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

CVSS 8.2EPSS 0.28900000000000003%Risiko 0.84
Quelle öffnen
Veröffentlicht
2026-07-20 08:16:28
Betroffene Versionen
<=2.1.0
Typ
Bibliothek
Zuletzt geändert
2026-07-22 12:17:09
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H