Back

CRITICAL

perl-App-cpanminus: Insecure HTTP in App::cpanminus Allows Code Execution Vulnerability

Published Aug 27, 2024

Description

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

Affected products

Remediation

Red Hat mitigation

A user can force cpanminus to use a HTTPS mirror using the --from command-line argument. This can be configured as a CLI option or as an environment variable. As a command line argument, replacing DISTNAME in the command with the name of the distribution you want to install: `$ cpanm --from https://www.cpan.org DISTNAME` As set with the environment variable: `$ export PERL_CPANM_OPT="--from https://www.cpan.org"`

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 27, 2024
Updated Sep 6, 2024
Reserved Aug 27, 2024
CISA Vulnrichment
Updated Aug 27, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 27, 2024
ENISA EUVD
Assigner mitre
Published Aug 27, 2024
Updated Sep 6, 2024
Exploited since n/a
EUVD-2024-41438