High severity8.1NVD Advisory· Published May 3, 2025· Updated Jun 17, 2026
CVE-2024-58134
CVE-2024-58134
Description
Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default.
These predictable default secrets can be exploited by an attacker to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mojolicious:mojolicious:*:*:*:*:*:perl:*:*+ 1 more
- cpe:2.3:a:mojolicious:mojolicious:*:*:*:*:*:perl:*:*range: >=0.999922,<=9.40
- (no CPE)range: >=0.999922
- Range: >=0.999922
- SRI/Mojoliciousv5Range: 0.999922
Patches
Vulnerability mechanics
References
11- github.com/hashcat/hashcat/pull/4090nvdIssue TrackingPatch
- github.com/mojolicious/mojo/pull/1791nvdIssue TrackingPatch
- github.com/mojolicious/mojo/pull/2200nvdIssue TrackingPatch
- www.synacktiv.com/publications/baking-mojolicious-cookiesnvdExploit
- medium.com/securing/baking-mojolicious-cookies-revisited-a-case-study-of-solving-security-problems-through-security-by-13da7c225802nvdThird Party Advisory
- metacpan.org/release/SRI/Mojolicious-9.39/source/lib/Mojolicious.pmnvdProduct
- docs.mojolicious.org/Mojolicious/Guides/FAQnvd
- github.com/mojolicious/mojo/pull/2252nvd
- lists.debian.org/debian-perl/2025/05/msg00016.htmlnvd
- lists.debian.org/debian-perl/2025/05/msg00017.htmlnvd
- lists.debian.org/debian-perl/2025/05/msg00018.htmlnvd
News mentions
0No linked articles in our index yet.