REDHAT-BUG-2218667: Medium severity CPAN CPAN.pm vulnerability
Published Jun 29, 2023
·Updated
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Affected Software
1 affected component
CPAN CPAN.pm<2.35
Event History
Jun 29, 2023
Data Sourced
via Red Hat·07:13 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2218667?
The vulnerability in REDHAT-BUG-2218667 is considered high severity due to the lack of TLS certificate verification.
2
How do I fix REDHAT-BUG-2218667?
To fix REDHAT-BUG-2218667, update CPAN.pm to version 2.35 or later.
3
Who is affected by REDHAT-BUG-2218667?
Anyone using CPAN.pm versions before 2.35 is affected by REDHAT-BUG-2218667.
4
What vulnerability does REDHAT-BUG-2218667 address?
REDHAT-BUG-2218667 addresses the vulnerability of unverified TLS certificates when downloading distributions over HTTPS.
5
What are the consequences of not addressing REDHAT-BUG-2218667?
Not addressing REDHAT-BUG-2218667 may expose users to potential man-in-the-middle attacks due to unverified TLS connections.