https://seclists.org/oss-sec/2023/q2/128: Perl's HTTP::Tiny has insecure TLS cert default, affecting CPAN.pm and other modules
Published May 7, 2023
·Updated
Affected Software
3 affected components
Perl HTTP::Tiny
CPAN CPAN.pm
GitLab GitLab::API::v4
Frequently Asked Questions
1
What is the severity of CVE-2023-31484?
CVE-2023-31484 is considered a high-severity vulnerability due to its impact on insecure TLS certificate handling in CPAN.pm.
2
How do I fix CVE-2023-31485?
To fix CVE-2023-31485, upgrade GitLab::API::v4 to a version that addresses the insecure TLS certificate issue.
3
What modules are affected by CVE-2023-31486?
CVE-2023-31486 affects the HTTP::Tiny module, which is used for making HTTP requests in Perl applications.
4
What are the implications of CVE-2023-31484 on software security?
The implications of CVE-2023-31484 include increased risk of man-in-the-middle attacks due to improper TLS certificate validation.
5
Is there a patch available for CVE-2023-31486?
Yes, a patch is available for CVE-2023-31486 in the latest release of the HTTP::Tiny module.