CVE-2024-58134: Mojolicious Insecure Secret Generation

Mojolicious applications and framework code should not use the predictable application moniker or insecure PRNGs like `rand` to generate session secrets or CSRF tokens. This allows an attacker to compute valid HMAC signatures and forge session cookies. Replace predictable secrets with strong cryptographic random strings (e.g. `Mojo::Util::urandom_urlsafe`).

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Generic
greprules fetch cve-2024-58134-mojolicious-insecure-secret-generation --engine opengrep

Description

Mojolicious applications and framework code should not use the predictable application moniker or insecure PRNGs like `rand` to generate session secrets or CSRF tokens. This allows an attacker to compute valid HMAC signatures and forge session cookies. Replace predictable secrets with strong cryptographic random strings (e.g. `Mojo::Util::urandom_urlsafe`).