CVE-2024-58135: Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default
Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default.
When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and used for authenticating and protecting the integrity of the application's sessions. This may allow an attacker to brute force the application's session keys.
Release 9.46 fixes the issue by providing high quality randomness, even in absence of CryptX.
Users should be aware that the update does not replace previously generated weak secrets. A secret generated with the previous version MUST be replaced to ensure the updated version is using a strong secret.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58135?
CVE-2024-58135 is considered a high severity vulnerability due to weak HMAC session secrets being generated.
How do I fix CVE-2024-58135?
To fix CVE-2024-58135, update your Mojolicious version to 9.40 or higher to ensure secure HMAC session secrets are used.
What versions are affected by CVE-2024-58135?
CVE-2024-58135 affects Mojolicious versions from 7.28 to 9.39 inclusive.
What is the main issue with CVE-2024-58135?
The main issue with CVE-2024-58135 is the generation of weak HMAC session secrets using the insecure rand() function.
How can weak HMAC secrets in CVE-2024-58135 impact my application?
Weak HMAC secrets may allow attackers to forge authentication tokens, potentially leading to unauthorized access.