OESA-2023-1420

    Dashboard / Vulnerabilities / OESA-2023-1420

    OESA-2023-1420

    Published: 8 Jul 2023Last Modified: 18 Aug 2026
    Upstream:

    Summary: perl-CPAN security update

    Details: The CPAN module automates or at least simplifies the make and install of perl modules and extensions. It includes some primitive searching capabilities and knows how to use LWP, HTTP::Tiny, Net::FTP and certain external download clients to fetch distributions from the net. The CPAN module also supports named and versioned *bundles* of modules. Bundles simplify handling of sets of related modules. Security Fix(es): CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.(CVE-2023-31484)

    Affected packages

    Package

    Name: perl-CPAN

    Purl: pkg:rpm/openEuler/perl-CPAN&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.27-4.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2023-1420 | CVE-DB