Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-37920

Опубликовано: 25 июл. 2023
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

A flaw was found in the python-certifi package. This issue occurs when the e-Tugra root certificate in Certifi is removed, resulting in an unspecified error that has an unknown impact and attack vector.

Отчет

While eTurgra certificates being marked as untrusted by Mozilla is significant from a trust and security standpoint, this is still considered a low severity issue. The certificates were removed from Mozilla's root store in July 2023, indicating a proactive response to security concerns. Additionally, Red Hat does not run its own root store program, but depends on Mozilla for ssl certificates and Microsoft for signing certificates. These certs are included and marked as don't trust and will not be removed until Mozilla removes them. Browsers are most at risk, which already understand and parse 'don't trust after'. If python-fi is required not to trust these certs, they should parse the 'don't trust after' attribute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python-certifiNot affected
Red Hat Ceph Storage 4python-certifiAffected
Red Hat Ceph Storage 5python-certifiAffected
Red Hat Ceph Storage 6python-certifiAffected
Red Hat Enterprise Linux 6ca-certificatesOut of support scope
Red Hat Enterprise Linux 7ca-certificatesOut of support scope
Red Hat Enterprise Linux 8python39:3.9/python3x-pipNot affected
Red Hat Enterprise Linux 8python3-azure-sdkNot affected
Red Hat OpenShift Container Platform 3.11python-certifiOut of support scope
Red Hat Openshift Container Storage 4python-certifiAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=2226586python-certifi: Removal of e-Tugra root certificate

EPSS

Процентиль: 31%
0.00115
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

CVSS3: 7.5
nvd
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.

CVSS3: 9.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
почти 2 года назад

Certifi is a curated collection of Root Certificates for validating th ...

CVSS3: 7.5
github
почти 2 года назад

Removal of e-Tugra root certificate

EPSS

Процентиль: 31%
0.00115
Низкий

9.1 Critical

CVSS3