CVE-2013-10075
קריטית 9.1
תיאור (מקור, אנגלית)
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/8/2026
- CWE
- CWE-672
מוצרים מושפעים
chorny: apache\
קישורים
- https://rt.cpan.org/Public/Bug/Display.html?id=83525 Issue TrackingMailing List
- http://www.openwall.com/lists/oss-security/2026/05/08/12 Mailing ListThird Party Advisory