CVE-2020-36829: High severity Mojolicious Mojolicious vulnerability
Published Apr 7, 2024
·Updated
The Mojolicious module before 8.65 for Perl is vulnerable to securecompare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.
Affected Software
2 affected components
Mojolicious Mojolicious>8.65
Perl Perl>1.74
Event History
Apr 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 8, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2020-36829?
CVE-2020-36829 is considered a medium severity vulnerability due to its potential for timing attacks.
2
How do I fix CVE-2020-36829?
To fix CVE-2020-36829, upgrade the Mojolicious module to version 8.65 or later.
3
Who is affected by CVE-2020-36829?
CVE-2020-36829 affects applications using Mojolicious versions prior to 8.65.
4
What type of attack is related to CVE-2020-36829?
CVE-2020-36829 is related to secure_compare timing attacks that can expose secret string lengths.
5
What versions of Perl are affected by CVE-2020-36829?
CVE-2020-36829 affects Perl versions prior to 1.74.