Lucene search

K
osvGoogleOSV:USN-5230-1
HistoryJan 24, 2022 - 1:44 p.m.

cpanminus vulnerability

2022-01-2413:44:44
Google
osv.dev
11
app::cpanminus
checksums files
signature verification
sensitive data
unauthorized code

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

48.8%

It was discovered that App::cpanminus did not properly verify CHECKSUMS files.
An attacker could possibly use this issue to bypass signature verification,
gaining access to sensitive data or possibly executing unauthorized code.