Improper Certificate Validation in HTTP Tiny - CVE-2023-31486

 

Improper Certificate Validation in HTTP Tiny - CVE-2023-31486

Published: May 1, 2023


Vulnerability identifier: #VU75606
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-31486
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to missing verification of the TLS certificate. A remote attacker can perform MitM attack and trick the application into downloading a malicious file.

Affected software

HTTP Tiny
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
macOS
openEuler
Oracle Solaris
Netezza Appliance
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
OpenShift Pipelines
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Oracle Communications Cloud Native Core Network Repository Function
Netcool Operations Insight
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
IBM Cloud Pak for Business Automation
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
OpenShift Virtualization
Red Hat Single Sign-On
Oracle Communications Cloud Native Core Network Slice Selection Function
perl-HTTP-Tiny
perl-HTTP-Tiny (Red Hat package)
perl-HTTP-Tiny-doc
perl-HTTP-Tiny-help
perl-HTTP-Tiny-tests
perl-Pod-Perldoc
perl-help
perl-libs
perl-debugsource
perl-devel
perl-debuginfo
perl
dev-lang/perl

How to mitigate CVE-2023-31486

Install updates from vendor's website.

Netezza Appliance - update to 1.0.0.1
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Runtimes - update to 1.2.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift GitOps - update to 1.9.3
OpenShift Pipelines - update to 1.10.6
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.3.1
OpenShift Virtualization - addressed in versions 4.12.9, 4.13.6, 4.14.1
OpenShift Logging - addressed in versions 5.7.10, 5.8.1
Red Hat Single Sign-On - update to 7.6.6
macOS - update to 15.2 24C101
perl-HTTP-Tiny - addressed in versions 0.033-3.7, 0.078-1
perl-HTTP-Tiny (Red Hat package) - addressed in versions 0.074-1.el8_8.2, 0.074-2.el8, 0.076-461.el9
perl-HTTP-Tiny-doc - addressed in versions 0.074-2.0.1, 0.088-1
perl-HTTP-Tiny - addressed in versions 0.074-2.0.1, 0.088-1
perl-HTTP-Tiny-help - addressed in versions 0.076-4, 0.080-2
perl-HTTP-Tiny - addressed in versions 0.076-4, 0.080-2
perl-HTTP-Tiny-tests - update to 0.088-1
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift Dev Spaces - update to 3.15.0
perl-Pod-Perldoc - update to 3.28.01-459
QRadar User Behavior Analytics - update to 4.1.16
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.13.45, 4.14.33, 4.16.3
perl-help - addressed in versions 5.28.3-8, 5.34.0-8
perl-libs - addressed in versions 5.28.3-8, 5.34.0-8
perl-debugsource - addressed in versions 5.28.3-8, 5.34.0-8
perl-devel - addressed in versions 5.28.3-8, 5.34.0-8
perl-debuginfo - addressed in versions 5.28.3-8, 5.34.0-8
perl - addressed in versions 5.28.3-8, 5.34.0-8
perl - update to 5.32.1-477
dev-lang/perl - update to 5.38.2
Red Hat Migration Toolkit for Applications - update to 6.2
Oracle Solaris - update to 11.4 SRU 62
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF034, 23.0.2-IF006

External References

Related Security Bulletins