cbcvebase.
CVE-2023-31484
published 2023-04-29

CVE-2023-31484: CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

PriorityP341high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.55%
72.3th percentile
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

Affected

10 ranges
VendorProductVersion rangeFixed in
applemacos_sequoia
cpanpm_projectcpanpm< 2.352.35
debianperl< perl 5.36.0-7+deb12u3 (bookworm)perl 5.36.0-7+deb12u3 (bookworm)
msrccbl2_perl_5.34.1-489_on_cbl_mariner_2.0
msrccbl2_perl_5.34.1-490_on_cbl_mariner_2.0
perlperl< 5.38.05.38.0
perlperl>= 0 < 5.32.1-4+deb11u45.32.1-4+deb11u4
perlperl>= 0 < 5.36.0-7+deb12u35.36.0-7+deb12u3
perlperl>= 0 < 5.38.2-25.38.2-2
perlperl>= 0 < 5.38.2-25.38.2-2

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.