Описание
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
cpanminus | unfixed | package | ||
cpanminus | postponed | trixie | package | |
cpanminus | postponed | bookworm | package | |
cpanminus | postponed | bullseye | package |
Примечания
https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
https://github.com/miyagawa/cpanminus/issues/611
https://github.com/miyagawa/cpanminus/pull/674
EPSS
Связанные уязвимости
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
ELSA-2024-10219: perl-App-cpanminus:1.7044 security update (MODERATE)
EPSS