High severity8.1NVD Advisory· Published Aug 27, 2024· Updated Jun 17, 2026
CVE-2024-45321
CVE-2024-45321
Description
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- Range: <=1.7047
- osv-coords9 versionspkg:rpm/almalinux/perl-App-cpanminuspkg:rpm/almalinux/perl-CPAN-DistnameInfopkg:rpm/almalinux/perl-CPAN-Meta-Checkpkg:rpm/almalinux/perl-File-pushdpkg:rpm/almalinux/perl-Module-CPANfilepkg:rpm/almalinux/perl-Parse-PMFilepkg:rpm/almalinux/perl-String-ShellQuotepkg:rpm/opensuse/perl-App-cpanminus&distro=openSUSE%20Tumbleweedpkg:rpm/rocky-linux/perl-App-cpanminus?distro=rocky-linux-9-x86-64&epoch=0
< 1.7044-14.1.el9_5+ 8 more
- (no CPE)range: < 1.7044-14.1.el9_5
- (no CPE)range: < 0.12-13.module_el8.6.0+2810+886f1911
- (no CPE)range: < 0.014-6.module_el8.10.0+3924+8d272be4
- (no CPE)range: < 1.014-6.module_el8.6.0+2851+b32f1bac
- (no CPE)range: < 1.1002-7.module_el8.6.0+2792+592c5e39
- (no CPE)range: < 0.41-7.module_el8.6.0+2851+b32f1bac
- (no CPE)range: < 1.04-24.module_el8.6.0+2810+886f1911
- (no CPE)range: < 1.7047-2.1
- (no CPE)range: < 0:1.7044-14.1.el9_5
Patches
Vulnerability mechanics
References
3- github.com/miyagawa/cpanminus/pull/674nvdIssue TrackingPatch
- security.metacpan.org/2024/08/26/cpanminus-downloads-code-using-insecure-http.htmlnvdExploitThird Party Advisory
- github.com/miyagawa/cpanminus/issues/611nvdIssue Tracking
News mentions
0No linked articles in our index yet.