HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
References
Configurations
History
29 Nov 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Nov 2024, 08:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2023/04/29/1 - Mailing List, Patch | |
References | () http://www.openwall.com/lists/oss-security/2023/05/03/3 - Mailing List, Patch | |
References | () http://www.openwall.com/lists/oss-security/2023/05/03/5 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2023/05/07/2 - Mailing List, Third Party Advisory | |
References | () https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/ - Mitigation, Patch, Third Party Advisory | |
References | () https://github.com/chansen/p5-http-tiny/pull/153 - Patch | |
References | () https://hackeriet.github.io/cpan-http-tiny-overview/ - Product | |
References | () https://www.openwall.com/lists/oss-security/2023/04/18/14 - Mailing List, Patch | |
References | () https://www.openwall.com/lists/oss-security/2023/05/03/4 - Mailing List, Third Party Advisory | |
References | () https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/ - Issue Tracking |
14 Jun 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary | HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. |
08 May 2023, 17:06
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://hackeriet.github.io/cpan-http-tiny-overview/ - Product | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2023/04/29/1 - Mailing List, Patch | |
References | (MISC) https://www.openwall.com/lists/oss-security/2023/04/18/14 - Mailing List, Patch | |
References | (MISC) https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/ - Mitigation, Patch, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2023/05/03/3 - Mailing List, Patch | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2023/05/03/5 - Mailing List | |
References | (MISC) https://www.openwall.com/lists/oss-security/2023/05/03/4 - Mailing List, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2023/05/07/2 - Mailing List, Third Party Advisory | |
References | (MISC) https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/ - Issue Tracking | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
CPE | cpe:2.3:a:http\:\:tiny_project:http\:\:tiny:0.082:*:*:*:*:*:*:* | |
CWE | CWE-295 |
08 May 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 May 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 May 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 May 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
29 Apr 2023, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
29 Apr 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-29 00:15
Updated : 2025-01-30 20:15
NVD link : CVE-2023-31486
Mitre link : CVE-2023-31486
CVE.ORG link : CVE-2023-31486
JSON object : View
Products Affected
http\
- \
perl
- perl
CWE
CWE-295
Improper Certificate Validation