First published: Fri Apr 28 2023(Updated: )
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanpm Project Cpanpm | <2.35 | |
Perl Perl | <5.38.0 | |
IBM Cognos Analytics | <=12.0-12.0.2 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP2 | |
F5 Traffix SDC | =5.1.0 | 5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-31484.
The severity of CVE-2023-31484 is high with a CVSS score of 8.1.
The affected software for CVE-2023-31484 includes CPAN.pm versions up to and excluding 2.35 and Perl versions up to and excluding 5.38.0.
CVE-2023-31484 is a vulnerability in CPAN.pm that allows an attacker to download distributions over HTTPS without verifying the TLS certificates.
To fix CVE-2023-31484, it is recommended to update CPAN.pm to a version 2.35 or higher.