PoC Index

CVE-2024-58134

HIGH 8.1EPSS 0.5%

Mojolicious versions from 0.999922 through 9.40 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default.These predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2025-05-03
Updated
2025-10-20

Proof-of-concept exploits (1)

References

Related