#VU100914 Download of code without integrity check in App-cpanminus - CVE-2024-45321
Published: November 26, 2024
App-cpanminus
MIYAGAWA
Description
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates via the insecure HTTP protocol. A remote attacker with ability to perform man-in-the-middle (MitM) attack can supply malicious code to the application and compromise the affected system.