
🚨Critical - Perl Module::Load Arbitrary Module Load / Code Execution (CVE-2011-10043) Perl's Module::Load before 0.22 didn't properly restrict module names in load(). A name starting with "::" could specify an arbitrary module path outside @INC, so an attacker who can influence the module name passed to load() could get an arbitrary module loaded and its code executed. This is an old (2011) bug only now assigned a CVE, fixed back in Module::Load 0.22. Real-world impact is conditional on an app passing attacker-controlled input into load() - uncommon - so the listed CVSS 9.8 (CISA-ADP) is an upper bound rather than a typical case. 👉Upgrade Module::Load to 0.22 or later.
Post summary
CVE-2011-10043 allows arbitrary module loading via Module::Load; the issue is mitigated by upgrading to 0.22 or later, and no active exploitation is reported.
