Security Advisories (1)
CPANSA-HTTP-Session2-2018-01 (2018-01-26)

HTTP::Session2 1.10 does not validate session id, this causes RCE depending on the session store you use.

NAME

HTTP::Session2::ClientStore - Client store

DESCRIPTION

This is a part of HTTP::Session2 library.

This module stores the data to the cookie value.

ClientStore specific constructor parameters

serializer: CodeRef

Serializer callback function.

Default: MIME::Base64::encode(Storable::nfreeze($_[0]), '' )

deserializer: CodeRef

Deserializer callback function.

Default: Storable::thaw(MIME::Base64::decode($_[0]))

ignore_old: Int

Ignore session data older than ignore_old value. You can specify this value in epoch time.