Описание
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Ссылки
- Mailing ListPatch
- Mailing ListPatch
- Mailing List
- Mailing List
- MitigationPatchThird Party Advisory
- ExploitIssue Tracking
- Release Notes
- Mailing ListPatch
- Mailing ListPatch
- Mailing ListPatch
- Mailing List
- Mailing List
- MitigationPatchThird Party Advisory
- ExploitIssue Tracking
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 2.35 (исключая)
cpe:2.3:a:cpanpm_project:cpanpm:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 5.38.0 (исключая)
cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01385
Низкий
8.1 High
CVSS3
Дефекты
CWE-295
CWE-295
Связанные уязвимости
CVSS3: 8.1
ubuntu
около 2 лет назад
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CVSS3: 7.4
redhat
около 2 лет назад
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CVSS3: 8.1
debian
около 2 лет назад
CPAN.pm before 2.35 does not verify TLS certificates when downloading ...
EPSS
Процентиль: 79%
0.01385
Низкий
8.1 High
CVSS3
Дефекты
CWE-295
CWE-295