CVE-2023-31484Improper Certificate Validation in Project Cpanpm

Severity
8.1HIGHNVD
EPSS
1.2%
top 21.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 29
Latest updateDec 11

Description

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages3 packages

NVDperl/perl< 5.38.0
Debianperl/perl< 5.32.1-4+deb11u4+3

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-31484: CPAN2023-04-29
GHSA
GHSA-5v8j-jfmm-6x86: CPAN2023-04-29
CVEList
CVE-2023-31484: CPAN2023-04-28

📋Vendor Advisories

6
Apple
CVE-2023-31484: macOS Sequoia 15.22024-12-11
Ubuntu
Perl vulnerability2023-06-05
Ubuntu
Perl vulnerability2023-05-29
Red Hat
perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS2023-04-29
Microsoft
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.2023-04-11