CVE-2023-37920
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- certifi/certifi · fedoraproject/fedora · netapp/active iq unified manager · netapp/management services for element software · netapp/management services for netapp hci · netapp/ontap mediator · netapp/ontap select deploy administration utility · netapp/solidfire \& hci storage node
- Source
- security-advisories@github.com
References
- https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909Patch
- https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7Vendor Advisory
- https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1AMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/Mailing List
- https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909Patch
- https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7Vendor Advisory
- https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1AMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/Mailing List
- https://security.netapp.com/advisory/ntap-20240912-0002/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.