Back to overview

CVE-2014-125112

CRITICAL
9.8
CVSS 3.1
Description
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.

Metadata

CVE ID
CVE-2014-125112
State
PUBLISHED
Assigner
CPANSec
Reserved
2025-07-08 15:24 UTC
Published
2026-03-26 02:04 UTC
Last updated
2026-03-26 14:53 UTC
Primary CWE
CWE-565
CWE-565 Reliance on Cookies without Validation and Integrity…
Vendor / Product
MIYAGAWA / Plack::Middleware::Session::Cookie
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
MIYAGAWA Plack::Middleware::Session::Cookie 0 ≤ 0.21
Weakness (CWE)
CWESourceDescription
CWE-565 cna CWE-565 Reliance on Cookies without Validation and Integrity Checking
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview