CPAN 2.28 allows Signature Verification Bypass.
The verify_SSL flag is missing from HTTP::Tiny, and allows a network attacker to MITM the connection if it is used by the CPAN client
To install CPAN, copy and paste the appropriate command in to your terminal.
cpanm
cpanm CPAN
CPAN shell
perl -MCPAN -e shell install CPAN
For more information on module installation, please visit the detailed CPAN module installation guide.