Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
References
Configurations
History
16 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/plack/Plack-Middleware-Session/commit/b7f0252269ba1bb812b5dc02303754fe94c808e4 - Patch | |
| CPE | cpe:2.3:a:plack:plack-middleware-session:*:*:*:*:*:*:*:* | |
| First Time |
Plack
Plack plack-middleware-session |
11 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
09 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 01:16
Updated : 2025-12-16 19:16
NVD link : CVE-2013-10031
Mitre link : CVE-2013-10031
CVE.ORG link : CVE-2013-10031
JSON object : View
Products Affected
plack
- plack-middleware-session
CWE
CWE-1254
Incorrect Comparison Logic Granularity
