Security Advisory

CVE-2014-125112

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-26 02:04:10
Last updated 2026-03-26 14:53:30
Assigner CPANSec
State PUBLISHED

Description

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when there is no secret used to sign the cookie.