Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
History

Fri, 08 May 2026 08:15:00 +0000

Type Values Removed Values Added
Description Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
Title Apache::Session versions through 1.94 for Perl re-creates deleted sessions
Weaknesses CWE-672
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-05-08T07:44:13.267Z

Reserved: 2026-04-20T11:38:29.675Z

Link: CVE-2013-10075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T08:16:43.463

Modified: 2026-05-08T08:16:43.463

Link: CVE-2013-10075

cve-icon Redhat

No data.