CVE-2023-31484
29.04.2023, 00:15
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cpanpm_project | cpanpm | 𝑥 < 2.35 |
| perl | perl | 𝑥 < 5.38.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| cpanpm_project | cpanpm | 𝑥 < 2.35 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References