Bug 2228392 (CVE-2023-31486) - CVE-2023-31486 http-tiny: insecure TLS cert default
Summary: CVE-2023-31486 http-tiny: insecure TLS cert default
Keywords:
Status: NEW
Alias: CVE-2023-31486
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2228395 2228396 2228397 2228398 2228409 2228410 2228411 2228412
Blocks: 2192430
TreeView+ depends on / blocked
 
Reported: 2023-08-02 10:20 UTC by TEJ RATHI
Modified: 2025-04-01 03:27 UTC (History)
23 users (show)

Fixed In Version: HTTP-Tiny 0.083-TRIAL
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:6542 0 None None None 2023-11-07 08:19:18 UTC
Red Hat Product Errata RHSA-2023:7174 0 None None None 2023-11-14 15:22:15 UTC
Red Hat Product Errata RHSA-2024:0422 0 None None None 2024-01-24 16:48:13 UTC
Red Hat Product Errata RHSA-2024:0579 0 None None None 2024-01-30 13:24:22 UTC
Red Hat Product Errata RHSA-2024:4430 0 None None None 2024-07-09 12:52:16 UTC

Description TEJ RATHI 2023-08-02 10:20:32 UTC
HTTP::Tiny v0.082, is a http client included in Perl (since v5.13.9) and also a standalone CPAN module. It does not verify TLS certificates by default requiring users to opt-in with the verify_SSL=>1 flag to verify the identity of the HTTPS server they are communicating with.

https://www.openwall.com/lists/oss-security/2023/04/18/14
https://github.com/chansen/p5-http-tiny/issues/134
https://github.com/chansen/p5-http-tiny/pull/153
https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/
https://hackeriet.github.io/cpan-http-tiny-overview/
https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/
https://github.com/advisories/GHSA-g56r-phrf-6pc4

Comment 1 TEJ RATHI 2023-08-02 10:24:53 UTC
Created perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228395]


Created perl:5.32/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228396]


Created perl:5.34/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228397]


Created perl:5.36/perl-HTTP-Tiny tracking bugs for this issue:

Affects: fedora-all [bug 2228398]

Comment 4 errata-xmlrpc 2023-11-07 08:19:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6542 https://access.redhat.com/errata/RHSA-2023:6542

Comment 5 errata-xmlrpc 2023-11-14 15:22:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:7174 https://access.redhat.com/errata/RHSA-2023:7174

Comment 7 errata-xmlrpc 2024-01-24 16:48:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2024:0422 https://access.redhat.com/errata/RHSA-2024:0422

Comment 8 errata-xmlrpc 2024-01-30 13:24:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:0579 https://access.redhat.com/errata/RHSA-2024:0579

Comment 12 errata-xmlrpc 2024-07-09 12:52:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:4430 https://access.redhat.com/errata/RHSA-2024:4430


Note You need to log in before you can comment on or make changes to this bug.