Description
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3926-1 | perl security update |
EUVD |
EUVD-2023-35789 | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
Ubuntu USN |
USN-6112-1 | Perl vulnerability |
Ubuntu USN |
USN-6112-2 | Perl vulnerability |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T21:48:25.528Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31484
Updated: 2025-11-03T21:48:25.528Z
Status : Modified
Published: 2023-04-29T00:15:09.000
Modified: 2025-11-03T22:16:19.470
Link: CVE-2023-31484
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN