CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
2023-04-29T00:15:09.000
2025-11-03T22:16:19.470
Modified
CVSSv3.1: 8.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | cpanpm_project | cpanpm | < 2.35 | Yes |
| Application | perl | perl | < 5.38.0 | Yes |