漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks
Vulnerability Description
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.
CVSS Information
N/A
Vulnerability Type
会话固定
Vulnerability Title
Catalyst-Plugin-Authentication 授权问题漏洞
Vulnerability Description
Catalyst-Plugin-Authentication是Catalyst开源的一个身份验证插件框架。 Catalyst-Plugin-Authentication 0.10_027之前版本存在授权问题漏洞,该漏洞源于认证后未自动更改会话ID,可能导致会话固定攻击。
CVSS Information
N/A
Vulnerability Type
N/A