CVE-2014-125112 identifies a critical remote code execution vulnerability in Plack::Middleware::Session::Cookie versions through 0.21 for Perl. This flaw allows an attacker to execute arbitrary code on the server during cookie deserialization when no secret is used to sign the cookie. With a CVSS score of 9.8, it presents a severe risk due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While highly severe, there is no evidence of active exploitation, and public exploit code is not available in common repositories like Metasploit or ExploitDB. Community discussion and media coverage are minimal, and it is not included in the CISA Known Exploited Vulnerabilities catalog, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 0.21CPE match | cpe:2.3:a:miyagawa:plack\:\:middleware\:\:session\:\:cookie:*:*:*:*:*:perl:*:* | ||
< 0.23CPE matchmatch criteria | cpe:2.3:a:miyagawa:plack\:\:middleware\:\:session\:\:cookie:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.