CPAN 2.28 allows Signature Verification Bypass.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16156
Reference (s):
- FEDORA:FEDORA-2022-21e8372c42
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/SZ32AJIV4RHJMLWLU5QULGKMMIHYOMDC/
- FEDORA:FEDORA-2022-84fd87f7eb
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/SD6RYOJII7HRJ6WVORFNVTYNOFY5JDXN/
- http://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html

