Описание
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
Ссылки
- Issue Tracking
- Issue TrackingPatch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7047 (включая)
cpe:2.3:a:app\:\:cpanminus_project:app\:\:cpanminus:*:*:*:*:*:perl:*:*
EPSS
Процентиль: 28%
0.00099
Низкий
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-494
CWE-494
Связанные уязвимости
CVSS3: 8.1
ubuntu
12 месяцев назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
CVSS3: 8.1
redhat
12 месяцев назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
CVSS3: 8.1
debian
12 месяцев назад
The App::cpanminus package through 1.7047 for Perl downloads code via ...
CVSS3: 9.8
github
12 месяцев назад
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
oracle-oval
9 месяцев назад
ELSA-2024-10219: perl-App-cpanminus:1.7044 security update (MODERATE)
EPSS
Процентиль: 28%
0.00099
Низкий
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-494
CWE-494