CVE-2023-31486 describes an insecure default TLS configuration in HTTP::Tiny versions prior to 0.083, a Perl core module, affecting various Perl-based HTTP clients. This vulnerability, rated 8.1 HIGH, allows for man-in-the-middle attacks due to a lack of default certificate verification, potentially leading to high impact on confidentiality, integrity, and availability without user interaction. While no public exploits or active exploitation have been observed, and community discussion is minimal, the inherent risk of unverified TLS connections remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.083CPE matchmatch criteria | cpe:2.3:a:http\:\:tiny_project:http\:\:tiny:*:*:*:*:*:*:*:* | ||
< 5.38.0CPE matchmatch criteria | cpe:2.3:a:perl:perl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-31486
Jul 11, 2023http-tiny: insecure TLS cert default
Apr 18, 2023HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.
Apr 11, 2023