Security Advisories (1)
CPANSA-HTTP-Session2-2018-01 (2018-01-26)

HTTP::Session2 1.10 does not validate session id, this causes RCE depending on the session store you use.

Changes for version 1.05 - 2014-08-01

  • Show warnings if the secret string is too short.

Modules

HTTP session management
Abstract base class for HTTP::Session2
(Deprecated)Client store

Provides

in lib/HTTP/Session2/Expired.pm
in lib/HTTP/Session2/Random.pm

Examples