Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-31484

Опубликовано: 29 апр. 2023
Источник: redhat
CVSS3: 7.4

Описание

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

A flaw was found in Perl's CPAN, which doesn't check TLS certificates when downloading content. This happens due to verify_SSL missing when suing the HTTP::Tiny library during the connection. This may allow an attacker to inject into the network path and perform a Man-In-The-Middle attack, causing confidentiality or integrity issues.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perlOut of support scope
Red Hat Enterprise Linux 7perlAffected
Red Hat Enterprise Linux 8perl-CPANFixedRHSA-2024:309422.05.2024
Red Hat Enterprise Linux 9perl-CPANFixedRHSA-2023:653907.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2218667perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 2 лет назад

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVSS3: 8.1
nvd
около 2 лет назад

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVSS3: 8.1
debian
около 2 лет назад

CPAN.pm before 2.35 does not verify TLS certificates when downloading ...

suse-cvrf
почти 2 года назад

Security update for perl

suse-cvrf
почти 2 года назад

Security update for perl

7.4 High

CVSS3