CVE-2024-58134: Mojolicious Insecure Secret Generationcve-2024-58134-mojolicious-insecure-secret-generation
Mojolicious applications and framework code should not use the predictable application moniker or insecure PRNGs like `rand` to generate session secrets or CSRF tokens. This allows an attacker to compute valid HMAC signatures and forge session cookies. Replace predictable secrets with strong cryptographic random strings (e.g. `Mojo::Util::urandom_urlsafe`).