File tree Expand file tree Collapse file tree 1 file changed +15
-0
lines changed Expand file tree Collapse file tree 1 file changed +15
-0
lines changed Original file line number Diff line number Diff line change @@ -20,6 +20,21 @@ advisories:
20
20
- https://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
21
21
- https://github.com/miyagawa/cpanminus/pull/638
22
22
reported : 2020-07-30
23
+ - affected_versions :
24
+ - <=1.7047
25
+ cves :
26
+ - CVE-2024-45321
27
+ description : |
28
+ The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
29
+ fixed_versions : []
30
+ github_security_advisory :
31
+ - GHSA-9mmm-86g7-vp9g
32
+ id : CPANSA-App-cpanminus-2024-01
33
+ references :
34
+ - https://github.com/miyagawa/cpanminus/issues/611
35
+ - https://github.com/miyagawa/cpanminus/pull/674
36
+ - https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
37
+ reported : 2024-08-27
23
38
cpansa_version : 2
24
39
distribution : App-cpanminus
25
40
last_checked : 1708150829
You can’t perform that action at this time.
0 commit comments