Re: [OE-core][dunfell][PATCH] perl: Fix CVE-2023-31486

2024-04-23 Thread Steve Sakoman
Dunfell has reached end of life and we are no longer taking changes. The final build was done on April 15. Steve On Tue, Apr 23, 2024 at 1:21 AM virendra thakur wrote: > > From: Soumya > > HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available > standalone on CPAN, has an

[OE-core][dunfell][PATCH] perl: Fix CVE-2023-31486

2024-04-23 Thread virendra thakur
From: Soumya HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. References: https://nvd.nist.gov/vuln/detail/CVE-2023-31486 Upstream patches: