Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.
https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_027/changes
https://metacpan.org/pod/Plack::Middleware::Session#change_id
https://metacpan.org/pod/Catalyst::Plugin::Session#change_session_id