Security Advisories (1)
CVE-2026-5083 (2026-04-08)

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems. Note that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN.

NAME

Ado::BuildPlugin - Custom routines for Ado::Plugin::* installation

SYNOPSIS

#Ado must be already installed  and 
#Ado::BuildPlugin should be somewhere in @INC
use Ado::BuildPlugin;
my $builder = Ado::BuildPlugin->new(..);
$builder->create_build_script();

DESCRIPTION

This is a subclass of Module::Build. We use Module::Build::API to add custom functionality so we can install Ado and its plugins in a location chosen by the user. To use this module for installing your plugins Build.PL should some how find it in @INC (may be via $ENV{PERL5LIB}).

This module and Ado::Build exist because of the additional install paths that we use beside lib and bin. These modules also can serve as examples for your own builders if you have some custom things to do during build, test, install and even if you need to add a new ACTION_* to your setup.

METHODS

Ado::BuildPlugin inherits all methods from Module::Build. It also imports create_build_script, process_etc_files, process_public_files, process_templates_files from Ado::Build.

AUTHOR

Красимир Беров (Krasimir Berov)

COPYRIGHT AND LICENSE

Copyright 2013-2014 Красимир Беров (Krasimir Berov).

This program is free software, you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License v3 (LGPL-3.0). You may copy, distribute and modify the software provided that modifications are open source. However, software that includes the license may release under a different license.

See http://opensource.org/licenses/lgpl-3.0.html for more information.