Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens.
That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 11 Jun 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function. | |
Title | Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens | |
Weaknesses | CWE-338 | |
References |
|

Status: PUBLISHED
Assigner: CPANSec
Published: 2025-06-11T17:09:50.664Z
Updated: 2025-06-11T17:57:28.026Z
Reserved: 2025-04-16T09:05:34.361Z
Link: CVE-2025-40915

Updated: 2025-06-11T17:56:38.434Z

Status : Awaiting Analysis
Published: 2025-06-11T17:15:42.793
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-40915

No data.