Vulnerability Description
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/mojolicious/mojo/commit/c16a56a9d6575ddc53d15e76d58f0ebcb0eeb
- https://github.com/mojolicious/mojo/issues/1185
- https://github.com/mojolicious/mojo/pull/1192
- https://metacpan.org/dist/Mojolicious/changes
- https://github.com/mojolicious/mojo/commit/c16a56a9d6575ddc53d15e76d58f0ebcb0eeb
- https://github.com/mojolicious/mojo/issues/1185
- https://github.com/mojolicious/mojo/pull/1192
- https://metacpan.org/dist/Mojolicious/changes
FAQ
What is CVE-2018-25100?
CVE-2018-25100 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.
How severe is CVE-2018-25100?
CVE-2018-25100 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25100?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.