Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqr8-7jwr-rhp7

Опубликовано: 25 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Removal of e-Tugra root certificate

Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.

e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found here.

Пакеты

Наименование

certifi

pip
Затронутые версииВерсия исправления

>= 2015.4.28, < 2023.7.22

2023.7.22

EPSS

Процентиль: 31%
0.00115
Низкий

7.5 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

CVSS3: 9.1
redhat
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

CVSS3: 7.5
nvd
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

CVSS3: 9.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating th ...

EPSS

Процентиль: 31%
0.00115
Низкий

7.5 High

CVSS3

Дефекты

CWE-345