CVE-2023-37920

critical

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

References

https://lists.fedoraproject.org/archives/list/[email protected]/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/

https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A

https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7

https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909

Details

Source: Mitre, NVD

Published: 2023-07-25

Updated: 2023-08-12

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical