ALAS2-2023-2093

Related Vulnerabilities: CVE-2023-31486  

HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. (CVE-2023-31486)

ALAS2-2023-2093


Amazon Linux 2 Security Advisory: ALAS-2023-2093
Advisory Release Date: 2023-06-21 19:11 Pacific
Advisory Updated Date: 2023-06-29 19:47 Pacific
Severity: Important

Issue Overview:

HTTP::Tiny 0.082, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. (CVE-2023-31486)


Affected Packages:

perl-HTTP-Tiny


Issue Correction:
Run yum update perl-HTTP-Tiny to update your system.

New Packages:
noarch:
    perl-HTTP-Tiny-0.033-3.amzn2.0.1.noarch

src:
    perl-HTTP-Tiny-0.033-3.amzn2.0.1.src