Описание
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cpanminus | unfixed | package | ||
| cpanminus | postponed | trixie | package | |
| cpanminus | postponed | bookworm | package | |
| cpanminus | postponed | bullseye | package |
Примечания
https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
https://github.com/miyagawa/cpanminus/issues/611
https://github.com/miyagawa/cpanminus/pull/674
EPSS
Процентиль: 59%
0.00383
Низкий
Связанные уязвимости
CVSS3: 8.1
ubuntu
больше 1 года назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
CVSS3: 8.1
redhat
больше 1 года назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
CVSS3: 8.1
nvd
больше 1 года назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
EPSS
Процентиль: 59%
0.00383
Низкий