Medium severity5.9NVD Advisory· Published Apr 29, 2023· Updated Jun 17, 2026
CVE-2023-31485
CVE-2023-31485
Description
GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- GitLab/API::v4description
- Range: <=0.26
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2023/04/29/1nvdMailing ListPatch
- www.openwall.com/lists/oss-security/2023/05/03/3nvdMailing ListPatch
- blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/nvdMitigationPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2023/04/18/14nvdMailing ListPatch
- www.openwall.com/lists/oss-security/2023/05/03/5nvdMailing List
- www.openwall.com/lists/oss-security/2023/05/07/2nvdMailing List
- github.com/bluefeet/GitLab-API-v4/pull/57nvdIssue Tracking
- github.com/chansen/p5-http-tiny/pull/151nvdIssue Tracking
News mentions
0No linked articles in our index yet.