{"id":"CVE-2023-31484","details":"CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.","modified":"2026-05-12T03:53:27.952436Z","published":"2023-04-28T00:00:00Z","related":["ALSA-2023:6539","ALSA-2024:3094","SUSE-SU-2023:2881-1","SUSE-SU-2023:2882-1","SUSE-SU-2024:1630-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/31xxx/CVE-2023-31484.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00017.html"},{"type":"WEB","url":"https://metacpan.org/dist/CPAN/changes"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/04/18/14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/31xxx/CVE-2023-31484.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BM6UW55CNFUTNGD5ZRKGUKKKFDJGMFHL/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LEGCEOKFJVBJ2QQ6S2H4NAEWTUERC7SB/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31484"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240621-0007/"},{"type":"FIX","url":"https://github.com/andk/cpanpm/pull/175"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/04/29/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/05/03/3"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/05/03/5"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/05/07/2"},{"type":"ARTICLE","url":"https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/andk/cpanpm","events":[{"introduced":"0"},{"fixed":"b69df18c4e8d7a6764aac7ba86461f6754fc25e7"}],"database_specific":{"cpe":"cpe:2.3:a:cpanpm_project:cpanpm:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.35"}]}}],"versions":["1.93_51","1.93_52","1.93_53","1.93_54","1.94_52","1.94_53","1.94_54","1.94_55","1.94_56","1.94_57","1.94_58","1.94_59","1.94_60","1.94_61","1.94_62","1.94_63","1.94_64","1.94_65","1.9600","1.97_51","1.9800","2.00","2.00-TRIAL","2.01-TRIAL","2.02-TRIAL","2.03-TRIAL","2.04-TRIAL","2.05","2.05-TRIAL","2.05-TRIAL2","2.06-TRIAL","2.07-TRIAL","2.08-TRIAL","2.09-TRIAL","2.10","2.10-TRIAL","2.12-TRIAL","2.13-TRIAL","2.14","2.14-TRIAL","2.15-TRIAL","2.16","2.16-TRIAL","2.16-TRIAL2","2.17-TRIAL","2.17-TRIAL2","2.18-TRIAL","2.20-TRIAL","2.21-TRIAL","2.22","2.22-TRIAL","2.23-TRIAL","2.24-TRIAL","2.25","2.25-TRIAL","2.26","2.27","2.27-TRIAL","2.27-TRIAL2","2.29","2.30-TRIAL","2.31-TRIAL","2.32-TRIAL","2.33","2.33-TRIAL","2.34","2.34-TRIAL"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31484.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/perl/perl5","events":[{"introduced":"0"},{"fixed":"76298ae68aa7796f0ffc05095b127d23f4b2de8f"}],"database_specific":{"cpe":"cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"5.38.0"}]}}],"versions":["GitLive-blead","if-0.0603","if-0.0604","if-0.0605","perl-1.0","perl-2.0","perl-3.000","perl-3.044","perl-4.0.00","perl-4.0.36","perl-5.000","perl-5.000o","perl-5.001","perl-5.001n","perl-5.002","perl-5.002_01","perl-5.003","perl-5.005","perl-5.6.0","perl-5.7.0","perl-5.7.1","perl-5.7.2","perl-5.7.3","perl-5.8.0","perl-5.9.0","perl-5.9.1","perl-5.9.2","perl-5.9.3","perl-5.9.4","perl-5.9.5","perl-5a2","perl-5a9","v5.10.0","v5.11.0","v5.11.1","v5.11.3","v5.11.4","v5.11.5","v5.12.0","v5.12.0-RC0","v5.12.0-RC1","v5.12.0-RC2","v5.12.0-RC3","v5.12.0-RC4","v5.12.0-RC5","v5.13.0","v5.13.1","v5.13.10","v5.13.11","v5.13.2","v5.13.3","v5.13.4","v5.13.5","v5.13.6","v5.13.7","v5.13.8","v5.13.9","v5.14.0","v5.14.0-RC1","v5.14.0-RC2","v5.14.0-RC3","v5.15.0","v5.15.1","v5.15.2","v5.15.3","v5.15.4","v5.15.5","v5.15.9","v5.16.0","v5.16.0-RC1","v5.16.0-RC2","v5.17.0","v5.17.2","v5.17.4","v5.17.6","v5.17.7","v5.17.7.0","v5.17.8","v5.17.9","v5.18.0","v5.18.0-RC1","v5.18.0-RC2","v5.18.0-RC3","v5.18.0-RC4","v5.19.0","v5.19.1","v5.19.11","v5.19.2","v5.19.3","v5.19.5","v5.19.7","v5.20.0","v5.20.0-RC1","v5.21.0","v5.21.1","v5.21.10","v5.21.11","v5.21.4","v5.21.5","v5.21.6","v5.21.8","v5.21.9","v5.22.0","v5.22.0-RC1","v5.22.0-RC2","v5.23.0","v5.23.1","v5.23.2","v5.23.3","v5.23.4","v5.23.6","v5.23.7","v5.24.0","v5.24.0-RC1","v5.24.0-RC2","v5.24.0-RC3","v5.24.0-RC4","v5.24.0-RC5","v5.25.0","v5.25.11","v5.25.2","v5.25.3","v5.25.4","v5.25.5","v5.25.7","v5.25.9","v5.26.0","v5.26.0-RC2","v5.27.0","v5.27.10","v5.27.11","v5.27.3","v5.27.5","v5.27.6","v5.27.7","v5.27.8","v5.28.0","v5.28.0-RC1","v5.28.0-RC2","v5.28.0-RC3","v5.28.0-RC4","v5.29.0","v5.29.1","v5.29.10","v5.29.5","v5.29.6","v5.29.7","v5.29.8","v5.29.9","v5.30.0","v5.30.0-RC1","v5.30.0-RC2","v5.31.0","v5.31.1","v5.31.11","v5.31.2","v5.31.3","v5.31.4","v5.31.5","v5.31.7","v5.32.0","v5.32.0-RC1","v5.33.0","v5.33.1","v5.33.2","v5.33.3","v5.33.4","v5.33.7","v5.33.8","v5.33.9","v5.34.0","v5.34.0-RC1","v5.34.0-RC2","v5.35.0","v5.35.10","v5.35.11","v5.35.3","v5.35.5","v5.35.6","v5.35.8","v5.35.9","v5.36.0","v5.36.0-RC3","v5.37.0","v5.37.1","v5.37.10","v5.37.11","v5.37.2","v5.37.3","v5.37.4","v5.37.5","v5.37.6","v5.37.7","v5.37.9","v5.38.0-RC1","v5.38.0-RC2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31484.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}