HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/ | patch mitigation third party advisory |
https://www.openwall.com/lists/oss-security/2023/04/18/14 | patch mailing list |
https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/ | issue tracking |
https://hackeriet.github.io/cpan-http-tiny-overview/ | product |
http://www.openwall.com/lists/oss-security/2023/04/29/1 | patch mailing list |
http://www.openwall.com/lists/oss-security/2023/05/03/3 | patch mailing list |
http://www.openwall.com/lists/oss-security/2023/05/03/5 | mailing list |
https://www.openwall.com/lists/oss-security/2023/05/03/4 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2023/05/07/2 | third party advisory mailing list |
https://github.com/chansen/p5-http-tiny/pull/153 | patch |
https://security.netapp.com/advisory/ntap-20241129-0011/ |