CVE-2024-58134

HIGH

Mojolicious <0.999922 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies.  An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

Scores

CVSS v3 8.1
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-331 CWE-321
Status published
Products (1)
mojolicious/mojolicious 0.999922 - 9.40
Published May 03, 2025
Tracked Since Feb 18, 2026