ALAS2-2023-2094

Related Vulnerabilities: CVE-2023-31486  

HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. (CVE-2023-31486)

ALAS2-2023-2094


Amazon Linux 2 Security Advisory: ALAS-2023-2094
Advisory Release Date: 2023-06-21 19:11 Pacific
Advisory Updated Date: 2023-06-29 19:47 Pacific
Severity: Important

Issue Overview:

HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. (CVE-2023-31486)


Affected Packages:

perl-Pod-Perldoc


Issue Correction:
Run yum update perl-Pod-Perldoc to update your system.

New Packages:
noarch:
    perl-Pod-Perldoc-3.20-4.amzn2.0.1.noarch

src:
    perl-Pod-Perldoc-3.20-4.amzn2.0.1.src