Replies: 2 comments
-
We have not tested older versions and therefore don't know which older versions work. |
Beta Was this translation helpful? Give feedback.
-
Looks like it starts breaking at 0.061.
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
Thanks for Mojolicious, including the new support for using CryptX to generate secure default session secrets. I'm looking at backporting that support to older Mojolicious in order to address CVE-2024-58135 in older releases of Debian.
Commit c820715 adding the support specifies that CryptX 0.080 is required. @kraih, are you sure it's required? Looking at the Changes for CryptX, it doesn't seem like the fixes in that release are essential to the new functionality.
Would it be possible for the reasons for requiring 0.080 to be expanded upon, and possibly the dependency bound weakened?
Thanks.
Beta Was this translation helpful? Give feedback.
All reactions