The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote malicious users to bypass intended certificate restrictions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
io-socket-ssl io-socket-ssl 1.35 |