Skip to content

Commit 517da70

Browse files
committed
CVE-2024-45321 for App::cpanminus
1 parent ca0e114 commit 517da70

File tree

1 file changed

+15
-0
lines changed

1 file changed

+15
-0
lines changed

cpansa/CPANSA-App-cpanminus.yml

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,21 @@ advisories:
2020
- https://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
2121
- https://github.com/miyagawa/cpanminus/pull/638
2222
reported: 2020-07-30
23+
- affected_versions:
24+
- <=1.7047
25+
cves:
26+
- CVE-2024-45321
27+
description: |
28+
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
29+
fixed_versions: []
30+
github_security_advisory:
31+
- GHSA-9mmm-86g7-vp9g
32+
id: CPANSA-App-cpanminus-2024-01
33+
references:
34+
- https://github.com/miyagawa/cpanminus/issues/611
35+
- https://github.com/miyagawa/cpanminus/pull/674
36+
- https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
37+
reported: 2024-08-27
2338
cpansa_version: 2
2439
distribution: App-cpanminus
2540
last_checked: 1708150829

0 commit comments

Comments
 (0)