CVE-2013-10031
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.05%
- CWE
- CWE-1254
- Published
- 2025-12-09
- Last modified
- 2026-03-15
Affected products
- MIYAGAWA Plack::Middleware::Session
Weakness type
Related vulnerabilities
- CVE-2026-34572 — CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
- CVE-2026-34570 — CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
- CVE-2026-27007 — OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation
- CVE-2022-39308 — GoCD API authentication of user access tokens subject to timing attack during comparison