Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs.
* Data::UUID returns v3 UUIDs, which are generated from known information and are unsuitable for security, as per RFC 9562.
* The nonces should be generated from a strong cryptographic source, as per RFC 7616.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Perl
Perl catalyst Authentication Credential Http |
|
Vendors & Products |
Perl
Perl catalyst Authentication Credential Http |
Mon, 11 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 11 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID returns v3 UUIDs, which are generated from known information and are unsuitable for security, as per RFC 9562. * The nonces should be generated from a strong cryptographic source, as per RFC 7616. | |
Title | Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl use insecurely generated nonces | |
Weaknesses | CWE-338 CWE-340 |
|
References |
|
|

Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-08-11T20:52:44.260Z
Reserved: 2025-04-16T09:05:34.362Z
Link: CVE-2025-40920

Updated: 2025-08-11T20:52:29.526Z

Status : Awaiting Analysis
Published: 2025-08-11T21:15:28.087
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-40920

No data.