Bug 2520677 (CVE-2026-15743)
| Summary: | CVE-2026-15743 perl-Catalyst-Plugin-Static-Simple: Catalyst::Plugin::Static::Simple: Information disclosure via public caching of authenticated responses | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Catalyst::Plugin::Static::Simple for Perl. The _serve_static method incorrectly sets the Cache-Control header to "public" for all responses. This misconfiguration allows intermediate proxies to store sensitive content, including responses from authenticated sessions, in shared caches. Consequently, an attacker could potentially access confidential information intended for other users, leading to unauthorized information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2536982 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-20 18:22:29 UTC
|