漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids
Vulnerability Description
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication tokens.
CVSS Information
N/A
Vulnerability Type
敏感数据的明文传输
Vulnerability Title
Catalyst::Plugin::Statsd 安全漏洞
Vulnerability Description
Catalyst::Plugin::Statsd是Robert Rothenberg个人开发者的一个用于采集应用运行指标并发送至统计系统的插件模块。 Catalyst::Plugin::Statsd 0.10.0及之前版本存在安全漏洞,该漏洞源于与statsd守护进程的通信信道未加密,可能导致用户会话ID泄露,攻击者可能利用会话ID作为认证令牌。
CVSS Information
N/A
Vulnerability Type
N/A