CVE-2023-31486
published 2023-04-29CVE-2023-31486: HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to…
PriorityP344high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.74%
75.3th percentile
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sequoia | — | — |
| debian | libhttp-tiny-perl | < libhttp-tiny-perl 0.088-1 (forky) | libhttp-tiny-perl 0.088-1 (forky) |
| debian | perl | < libhttp-tiny-perl 0.088-1 (forky) | libhttp-tiny-perl 0.088-1 (forky) |
| msrc | cbl2_perl_5.34.1-489_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_perl_5.34.1-490_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_perl_5.30.3-3_on_cbl_mariner_1.0 | — | — |
| perl | perl | < 5.38.0 | 5.38.0 |
| perl | perl | >= 0 < 5.38.2-2 | 5.38.2-2 |
| perl | perl | >= 0 < 5.38.2-2 | 5.38.2-2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1LOW
vendor_msrc8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-31486: HTTP::Tiny before 0
osv·2023-04-29·CVSS 8.1
CVE-2023-31486 [HIGH] CVE-2023-31486: HTTP::Tiny before 0
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
GHSA
GHSA-g56r-phrf-6pc4: HTTP::Tiny 0
ghsa_unreviewed·2023-04-29
CVE-2023-31486 CWE-295 GHSA-g56r-phrf-6pc4: HTTP::Tiny 0
HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Apple
CVE-2023-31486: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 8.1
CVE-2023-31486 [HIGH] CVE-2023-31486: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2023-31486
Component: CVE-2023-31486
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Perl) — CVE-2023-31486
vendor_oracle·2024-01-15·CVSS 8.1
CVE-2023-31486 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Perl) — CVE-2023-31486
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Perl) vulnerability
CVE: CVE-2023-31486
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
http-tiny: insecure TLS cert default
vendor_redhat·2023-04-18·CVSS 8.1
CVE-2023-31486 [HIGH] CWE-1188 http-tiny: insecure TLS cert default
http-tiny: insecure TLS cert default
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
A vulnerability was found in Tiny, where a Perl core module and standalone CPAN package, does not verify TLS certificates by default. Users need to explicitly enable certificate verification with the verify_SSL=>1 flag to ensure secure HTTPS connections. This oversight can potentially expose applications to man-in-the-middle (MITM) attacks, where an attacker might intercept and manipulate data transmitted between the client and server.
Statement: This vulnerability is rated as a moderate severity because, it does not compromise data or credentials, it exposes users to sign
Microsoft
HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.
vendor_msrc·2023-04-11·CVSS 8.1
CVE-2023-31486 [HIGH] CWE-295 HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.
HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Debian
CVE-2023-31486: libhttp-tiny-perl - HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalon...
vendor_debian·2023·CVSS 8.1
CVE-2023-31486 [HIGH] CVE-2023-31486: libhttp-tiny-perl - HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalon...
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Scope: local
bookworm: open
forky: resolved (fixed in 0.088-1)
sid: resolved (fixed in 0.088-1)
trixie: resolved (fixed in 0.088-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/04/29/1http://www.openwall.com/lists/oss-security/2023/05/03/3http://www.openwall.com/lists/oss-security/2023/05/03/5http://www.openwall.com/lists/oss-security/2023/05/07/2https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/https://github.com/chansen/p5-http-tiny/pull/153https://hackeriet.github.io/cpan-http-tiny-overview/https://www.openwall.com/lists/oss-security/2023/04/18/14https://www.openwall.com/lists/oss-security/2023/05/03/4https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/http://www.openwall.com/lists/oss-security/2023/04/29/1http://www.openwall.com/lists/oss-security/2023/05/03/3http://www.openwall.com/lists/oss-security/2023/05/03/5http://www.openwall.com/lists/oss-security/2023/05/07/2https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/https://github.com/chansen/p5-http-tiny/pull/153https://hackeriet.github.io/cpan-http-tiny-overview/https://security.netapp.com/advisory/ntap-20241129-0011/https://www.openwall.com/lists/oss-security/2023/04/18/14https://www.openwall.com/lists/oss-security/2023/05/03/4https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/
2023-04-29
Published