← Back to CVE search

CVE-2013-10075

Apache::Session

Description

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.

CVSS 9.1EPSS 0.356%Risk 0.94
View source
Published
2026-05-08 08:16:43
Affected versions
<=1.94
Type
Library
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N