Skip to content

Commit

Permalink
CVE-2024-453212 for App::cpanminus
Browse files Browse the repository at this point in the history
  • Loading branch information
stigtsp committed Sep 8, 2024
1 parent ca0e114 commit a196098
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions cpansa/CPANSA-App-cpanminus.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,21 @@ advisories:
- https://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
- https://github.com/miyagawa/cpanminus/pull/638
reported: 2020-07-30
- affected_versions:
- <=1.7047
cves:
- CVE-2024-45321
description: |
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
fixed_versions: []
github_security_advisory:
- GHSA-9mmm-86g7-vp9g
id: CPANSA-App-cpanminus-2024-01
references:
- https://github.com/miyagawa/cpanminus/issues/611
- https://github.com/miyagawa/cpanminus/pull/674
- https://security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.html
reported: 2024-08-27
cpansa_version: 2
distribution: App-cpanminus
last_checked: 1708150829
Expand Down

0 comments on commit a196098

Please sign in to comment.