CVE-2023-31486 — Improper Certificate Validation in Perl
Severity
8.1HIGHNVD
EPSS
0.6%
top 30.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
1
Timeline
PublishedApr 29
Latest updateDec 11
Description
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9
Patches
🔴Vulnerability Details
3📋Vendor Advisories
5Microsoft▶
HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.↗2023-04-11
Debian▶
CVE-2023-31486: libhttp-tiny-perl - HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalon...↗2023