9.8

CVE-2025-15578

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teejay ≫ Maypole SwPlatform perl Version >= 2.10 <= 2.13
Teejay ≫ Maypole Version 2.111 SwPlatform perl
Teejay ≫ Maypole Version 2.121 SwPlatform perl
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.193
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

https://metacpan.org/dist/Maypole/source/lib/Maypole/Session.pm#L43
Issue Tracking