Security Advisories (1)
CVE-2026-5083 (2026-04-08)

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems. Note that Ado is no longer maintained, and has been removed from the CPAN index. It is still available on BackPAN.

NAME

Ado::Sessions::File - manage sessions stored in files

DESCRIPTION

Ado::Sessions::File manages sessions for Ado. All data gets serialized with Mojo::JSON and stored Base64 encoded in a file. A cookie or a request parameter can be used to share the session id between the server and the user agents.

ATTRIBUTES

Ado::Sessions::File inherits all attributes from Ado::Sessions and implements the following new ones.

dstdir

Path where to store session data files.

METHODS

absfile

Compose absolute path to session data file.

cleanup

This method is a garbage collector. Cleans up expired session files.

dstfile

File name of the session data file.

load

Load session data from file.

store

Store session data in file.

SEE ALSO

Mojolicious::Sessions, Ado::Sessions::Database