CVE-2023-31484

Source
https://cve.org/CVERecord?id=CVE-2023-31484
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31484.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-31484
Aliases
Downstream
Related
Published
2023-04-29T00:15:09Z
Modified
2026-02-13T08:28:18.269341Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

References

Affected packages

Git / github.com/andk/cpanpm

Affected ranges

Type
GIT
Repo
https://github.com/andk/cpanpm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.93_51
1.93_52
1.93_53
1.93_54
1.94
1.94_52
1.94_53
1.94_54
1.94_55
1.94_56
1.94_57
1.94_58
1.94_59
1.94_60
1.94_61
1.94_62
1.94_63
1.94_64
1.94_65
1.9600
1.97_51
1.9800
2.*
2.00
2.00-TRIAL
2.01-TRIAL
2.02-TRIAL
2.03-TRIAL
2.04-TRIAL
2.05
2.05-TRIAL
2.05-TRIAL2
2.06-TRIAL
2.07-TRIAL
2.08-TRIAL
2.09-TRIAL
2.10
2.10-TRIAL
2.12-TRIAL
2.13-TRIAL
2.14
2.14-TRIAL
2.15-TRIAL
2.16
2.16-TRIAL
2.16-TRIAL2
2.17-TRIAL
2.17-TRIAL2
2.18-TRIAL
2.20-TRIAL
2.21-TRIAL
2.22
2.22-TRIAL
2.23-TRIAL
2.24-TRIAL
2.25
2.25-TRIAL
2.26
2.27
2.27-TRIAL
2.27-TRIAL2
2.28
2.28-TRIAL
2.29
2.30-TRIAL
2.31-TRIAL
2.32-TRIAL
2.33
2.33-TRIAL
2.34
2.34-TRIAL

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31484.json"