CVE Vulnerabilities

CVE-2023-31486

Improper Certificate Validation

Published: Apr 29, 2023 | Modified: Jan 30, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Http::tinyHttp::tiny_project*0.083 (excluding)
Red Hat Enterprise Linux 8RedHatperl-HTTP-Tiny-0:0.074-2.el8*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatperl-HTTP-Tiny-0:0.074-1.el8_6.1*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatperl-HTTP-Tiny-0:0.074-1.el8_8.2*
Red Hat Enterprise Linux 9RedHatperl-HTTP-Tiny-0:0.076-461.el9*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatperl-HTTP-Tiny-0:0.076-461.el9_2*
Libhttp-tiny-perlUbuntubionic*
Libhttp-tiny-perlUbuntudevel*
Libhttp-tiny-perlUbuntuesm-apps/bionic*
Libhttp-tiny-perlUbuntuesm-apps/focal*
Libhttp-tiny-perlUbuntuesm-apps/jammy*
Libhttp-tiny-perlUbuntuesm-apps/xenial*
Libhttp-tiny-perlUbuntufocal*
Libhttp-tiny-perlUbuntujammy*
Libhttp-tiny-perlUbuntukinetic*
Libhttp-tiny-perlUbuntulunar*
Libhttp-tiny-perlUbuntutrusty*
Libhttp-tiny-perlUbuntuupstream*
Libhttp-tiny-perlUbuntuxenial*
PerlUbuntubionic*
PerlUbuntudevel*
PerlUbuntuesm-infra-legacy/trusty*
PerlUbuntuesm-infra/bionic*
PerlUbuntuesm-infra/focal*
PerlUbuntuesm-infra/xenial*
PerlUbuntufocal*
PerlUbuntujammy*
PerlUbuntukinetic*
PerlUbuntulunar*
PerlUbuntutrusty*
PerlUbuntutrusty/esm*
PerlUbuntuupstream*
PerlUbuntuxenial*

Potential Mitigations

References