HackTesting
HomeArticlesTagsContact

CVE-2023-31486

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

References

https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/
https://www.openwall.com/lists/oss-security/2023/04/18/14
https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/
https://hackeriet.github.io/cpan-http-tiny-overview/
http://www.openwall.com/lists/oss-security/2023/04/29/1
http://www.openwall.com/lists/oss-security/2023/05/03/3
http://www.openwall.com/lists/oss-security/2023/05/03/5
https://www.openwall.com/lists/oss-security/2023/05/03/4
http://www.openwall.com/lists/oss-security/2023/05/07/2
https://github.com/chansen/p5-http-tiny/pull/153
Published
Apr 28, 2023 00:00:00 UTC
Updated
Jan 30, 2025 19:26:26 UTC
Reserved
Apr 28, 2023 00:00:00 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2025 HackTesting. All rights reserved.