REDHAT-BUG-1067180: Medium severity Perl CGI::Application vulnerability
It was reported [1],[2] that the CGI::Application perl module suffered from a flaw where, in certain cases, it would unexpectedly dump a complete set of web query data and server environment information as an error page. This could allow unintended disclosure of sensitive information.
A suggested fix is available [3] and the commit that caused the problem [4] was most likely introduced in version 4.19.
[1] https://rt.cpan.org/Public/Bug/Display.html?id=84403 [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=739505 [3] https://github.com/markstos/CGI--Application/pull/15 [4] https://github.com/markstos/CGI--Application/commit/61d327646f01fe
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1067180?
The severity of REDHAT-BUG-1067180 is considered high due to the potential for sensitive information disclosure.
How do I fix REDHAT-BUG-1067180?
To fix REDHAT-BUG-1067180, update the Perl CGI::Application module to a version later than 4.19 that addresses this vulnerability.
What type of information could be exposed by REDHAT-BUG-1067180?
REDHAT-BUG-1067180 could expose sensitive web query data and server environment information.
Which versions of CGI::Application are affected by REDHAT-BUG-1067180?
CGI::Application versions from 4.19 and earlier are affected by REDHAT-BUG-1067180.
Who reported the vulnerability REDHAT-BUG-1067180?
The vulnerability REDHAT-BUG-1067180 was reported by users in the developer community related to the CGI::Application module.