CPAN.pm before 2.35 does not verify TLS certificates when downloading
distributions over HTTPS.
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and
available standalone on CPAN, has an insecure default TLS
configuration where users must opt in to verify certificates.
References:
https://nvd.nist.gov/vuln/detail/CVE-2023-31484https://nvd.nist.gov/vuln/detail/CVE-2023-31486
Upstream patches:
9c9837028777f557ef84a22785783b
(From OE-Core rev: f4fe9861d6aebd971a3120a0eb43f752c73ce2fb)
Signed-off-by: Soumya <soumya.sambu@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>