Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-31484
HistoryApr 29, 2023 - 12:00 a.m.

CVE-2023-31484

2023-04-2900:00:00
ubuntu.com
ubuntu.com
52
cpan.pm
tls certificates
https
perl codebase
fix available

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

75.5%

CPAN.pm before 2.35 does not verify TLS certificates when downloading
distributions over HTTPS.

Bugs

Notes

Author Note
ccdm94 the fix released to cpanpm (commit 9c98370) can be applied to the perl codebase to fix the issue. The perl upstream has fixed the issue through commit 96ea0b9b, which is actually an import of CPAN v2.36.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchperl< 5.26.1-6ubuntu0.7UNKNOWN
ubuntu20.04noarchperl< 5.30.0-9ubuntu0.4UNKNOWN
ubuntu22.04noarchperl< 5.34.0-3ubuntu1.2UNKNOWN
ubuntu22.10noarchperl< 5.34.0-5ubuntu1.2UNKNOWN
ubuntu23.04noarchperl< 5.36.0-7ubuntu0.23.04.1UNKNOWN
ubuntu14.04noarchperl< 5.18.2-2ubuntu1.7+esm5UNKNOWN
ubuntu16.04noarchperl< 5.22.1-9ubuntu0.9+esm2UNKNOWN

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

75.5%