Description
GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
References (8)
Core 8
Core References
Mitigation, Patch, Third Party Advisory
https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/
Issue Tracking
https://github.com/bluefeet/GitLab-API-v4/pull/57
Issue Tracking
https://github.com/chansen/p5-http-tiny/pull/151
Mailing List, Patch
https://www.openwall.com/lists/oss-security/2023/04/18/14
Mailing List, Patch mailing-list
http://www.openwall.com/lists/oss-security/2023/04/29/1
Mailing List, Patch mailing-list
http://www.openwall.com/lists/oss-security/2023/05/03/3
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2023/05/03/5
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2023/05/07/2
Scores
CVSS v3
5.9
EPSS
0.0065
EPSS Percentile
46.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (1)
gitlab\/\
< 0.26
Published
Apr 29, 2023
Tracked Since
Feb 18, 2026