Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16154

Опубликовано: 23 нояб. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

A flaw was found in the way the perl-App-cpanminus performed verification of package signatures stored in CHECKSUMS files. A malicious or compromised CPAN server used by a user, or a man-in-the-middle attacker, could use this flaw to bypass signature verification.

Меры по смягчению последствий

This issue can be mitigated by instructing perl-App-cpanminus to only use trusted CPAN mirrors (www.cpan.org or cpan.metacpan.org) and use HTTPS for communication with CPAN servers. The cpanm command can be configured to use the specific CPAN mirror using the --from command line option by running it as:

cpanm --from https://www.cpan.org ...

You can also set environment variable PERL_CPANM_OPT to include this command line option to avoid having to specify the URL for every cpanm invocation:

export PERL_CPANM_OPT="--from https://www.cpan.org"

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-App-cpanminusOut of support scope
Red Hat Enterprise Linux 8perl-App-cpanminus:1.7044/perl-App-cpanminusWill not fix
Red Hat Enterprise Linux 9perl-App-cpanminusWill not fix
Red Hat Software Collectionsrh-perl530-perl-App-cpanminusWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2035341perl-App-cpanminus: Bypass of verification of signatures in CHECKSUMS files

EPSS

Процентиль: 7%
0.00026
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

CVSS3: 7.8
nvd
около 4 лет назад

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

CVSS3: 7.8
debian
около 4 лет назад

The App::cpanminus package 1.7044 for Perl allows Signature Verificati ...

suse-cvrf
почти 4 года назад

Security update for perl-App-cpanminus

github
почти 4 года назад

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

EPSS

Процентиль: 7%
0.00026
Низкий

7.8 High

CVSS3