Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-23491

Опубликовано: 07 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.8

Описание

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

РелизСтатусПримечание
bionic

released

20211016ubuntu0.18.04.1
devel

released

20211016ubuntu1
esm-infra-legacy/trusty

not-affected

20211016~14.04.1~esm1
esm-infra/bionic

not-affected

20211016ubuntu0.18.04.1
esm-infra/focal

not-affected

20211016ubuntu0.20.04.1
esm-infra/xenial

released

20211016~16.04.1~esm2
focal

released

20211016ubuntu0.20.04.1
jammy

released

20211016ubuntu0.22.04.1
kinetic

released

20211016ubuntu0.22.10.1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 12%
0.00042
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS3: 6.8
nvd
больше 2 лет назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS3: 6.8
debian
больше 2 лет назад

Certifi is a curated collection of Root Certificates for validating th ...

suse-cvrf
больше 2 лет назад

Security update for python-certifi

CVSS3: 7.5
redos
около 2 лет назад

Уязвимость python-certifi

EPSS

Процентиль: 12%
0.00042
Низкий

6.8 Medium

CVSS3