Apache::Session versions through 1.94 for Perl re-creates deleted sessions.
The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can lead to sessions being revived, potentially with data that was to be deleted.
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Apache::session | Chorny | * | 1.94 (including) |
| Libapache-session-perl | Ubuntu | esm-apps/xenial | * |