{ "id": "CVE-2023-31486", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-29T00:15:09.083", "lastModified": "2023-04-29T00:15:09.083", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates." } ], "metrics": {}, "references": [ { "url": "https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/", "source": "cve@mitre.org" }, { "url": "https://hackeriet.github.io/cpan-http-tiny-overview/", "source": "cve@mitre.org" }, { "url": "https://www.openwall.com/lists/oss-security/2023/04/18/14", "source": "cve@mitre.org" }, { "url": "https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/", "source": "cve@mitre.org" } ] }