Signature Verification Bypass in CPAN by CPAN 2.28
CVE-2020-16156
7.8HIGH
Key Information:
- Vendor
Perl
- Vendor
- CVE Published:
- 13 December 2021
What is CVE-2020-16156?
The vulnerability in CPAN 2.28 allows attackers to bypass signature verification, potentially leading to the installation of malicious packages. This flaw compromises the integrity of package management by allowing unverified changes to be accepted, thereby exposing systems to security risks. Users are encouraged to apply available updates and security patches to mitigate the risks associated with this vulnerability.