216.73.216.233

CVE-2009-10007

· Published 09/06/2026 09:16 · Modified 09/06/2026 16:16

Labels: CVE-2009-10007 2026-06-099b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2009-10007CWE-384

Essential information

Published
09/06/2026 09:16
Modified
09/06/2026 16:16
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
catalyst / catalyst plugin authentication cpe:2.3:a:catalyst:catalyst_plugin_authentication:<0.10_027:*:*:*:*:*:*:*

References