Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43fp-rhv2-5gv8

Опубликовано: 07 дек. 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.9
CVSS3: 6.8

Описание

Certifi removing TrustCor root certificate

Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store.

TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found here.

Пакеты

Наименование

certifi

pip
Затронутые версииВерсия исправления

>= 2017.11.05, < 2022.12.07

2022.12.07

EPSS

Процентиль: 13%
0.00044
Низкий

5.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.8
ubuntu
почти 3 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS3: 7.5
redhat
почти 3 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS3: 6.8
nvd
почти 3 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS3: 6.8
debian
почти 3 года назад

Certifi is a curated collection of Root Certificates for validating th ...

suse-cvrf
почти 3 года назад

Security update for python-certifi

EPSS

Процентиль: 13%
0.00044
Низкий

5.9 Medium

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-345