Search CVE reports


Toggle filters

51 – 60 of 238 results


CVE-2023-31486

Medium priority
Ignored

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

2 affected packages

libhttp-tiny-perl, perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhttp-tiny-perl Ignored Ignored Ignored
perl Ignored Ignored Ignored
Show less packages

CVE-2023-31485

Medium priority
Ignored

GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.

1 affected package

libgitlab-api-v4-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgitlab-api-v4-perl Not affected Ignored Ignored Ignored
Show less packages

CVE-2023-31484

Medium priority
Fixed

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Fixed Fixed
Show less packages

CVE-2020-36659

Medium priority
Needs evaluation

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE:...

1 affected package

libapache-session-browseable-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-session-browseable-perl Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-36658

Medium priority
Fixed

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can,...

1 affected package

libapache-session-ldap-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libapache-session-ldap-perl Not affected Fixed Fixed
Show less packages

CVE-2023-24038

Medium priority

Some fixes available 6 of 7

The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

1 affected package

libhtml-stripscripts-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhtml-stripscripts-perl Fixed Fixed Fixed
Show less packages

CVE-2018-25052

Medium priority
Needs evaluation

A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm of the component Session ID...

1 affected package

libcatalyst-plugin-session-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcatalyst-plugin-session-perl Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2022-31081

Medium priority

Some fixes available 6 of 7

HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It...

1 affected package

libhttp-daemon-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhttp-daemon-perl Fixed Fixed Fixed
Show less packages

CVE-2022-23935

Medium priority
Vulnerable

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

1 affected package

libimage-exiftool-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libimage-exiftool-perl Not affected Needs evaluation Vulnerable Vulnerable
Show less packages

CVE-2020-16156

Medium priority

Some fixes available 7 of 9

CPAN 2.28 allows Signature Verification Bypass.

1 affected package

perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
perl Fixed Fixed Fixed
Show less packages