vulnerability

FreeBSD: VID-c323bab5-80dd-11f0-97c4-40b034429ecf (CVE-2025-40920): p5-Catalyst-Authentication-Credential-HTTP -- Insecure source of randomness

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:P/A:P)
Published
Aug 24, 2025
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

perl-catalyst project reports: Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs.* Data::UUID returns v3 UUIDs, which are generated from known information and are unsuitable for security, as per RFC 9562. * The nonces should be generated from a strong cryptographic source, as per RFC 7616.

Solution

freebsd-upgrade-package-p5-catalyst-authentication-credential-http
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.