CVE-2009-10007
Catalyst::Plugin::Authentication for Perl before version 0.10_027 is vulnerable to session fixation, allowing attackers to hijack user sessions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Catalyst::Plugin::Authentication for Perl older than 0.10_027, typically web applications built with the Catalyst framework.
Real-world impact
An attacker who obtains a session ID cookie can impersonate the victim, gaining unauthorized access to the application.
Why this severity
The CVSS score of 9.1 reflects the high impact of the vulnerability: it requires no user interaction, has no authentication or privilege requirement, and allows an attacker to fully compromise confidentiality and integrity of the session.
What to do about it
- 01Upgrade Catalyst::Plugin::Authentication to version 0.10_027 or later.
- 02Restart the application to apply the new version.
NVD-referenced vendor advisory
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.