Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-43936.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-43936
Upstream
Published
2024-04-08T00:15:07Z
Modified
2026-04-01T05:15:22.661994Z
Summary
CVE-2020-36829 affecting package perl-Mojolicious 8.57-3
Details

The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.

References

Affected packages

Azure Linux:2 / perl-Mojolicious

Package

Name
perl-Mojolicious
Purl
pkg:rpm/azure-linux/perl-Mojolicious

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
8.57-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-43936.json"