First published: Mon Dec 13 2021(Updated: )
The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CPAN | =checksums_project-cpan\ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16155 has a medium severity rating due to its potential impact on data integrity.
To fix CVE-2020-16155, upgrade the CPAN::Checksums package to a version that addresses the vulnerability.
CVE-2020-16155 affects versions of the CPAN::Checksums package prior to the fixed release.
CVE-2020-16155 may lead to issues with the verification of signed data, potentially compromising data integrity.
There are no specific workarounds; updating to a secure version is the recommended approach.