Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-39689

Опубликовано: 05 июл. 2024
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS3: 7.5

Описание

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from GLOBALTRUST. Certifi 2024.7.04 removes root certificates from GLOBALTRUST from the root store. These are in the process of being removed from Mozilla's trust store. GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

РелизСтатусПримечание
devel

ignored

see notes
esm-apps/xenial

ignored

see notes
esm-infra/bionic

ignored

see notes
esm-infra/focal

ignored

see notes
focal

ignored

end of standard support, was ignored [see notes]
jammy

ignored

see notes
mantic

ignored

end of life, was needs-triage
noble

ignored

see notes
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

ignored

see notes
esm-apps/bionic

ignored

see notes
esm-apps/focal

ignored

see notes
esm-apps/jammy

ignored

see notes
esm-apps/noble

ignored

see notes
esm-apps/xenial

ignored

see notes
esm-infra-legacy/trusty

ignored

see notes
focal

ignored

end of standard support, was ignored [see notes]
jammy

ignored

see notes
mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 83%
0.01928
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
12 месяцев назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

CVSS3: 7.5
nvd
12 месяцев назад

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

CVSS3: 7.5
debian
12 месяцев назад

Certifi is a curated collection of Root Certificates for validating th ...

CVSS3: 7.5
redos
9 месяцев назад

Уязвимость ca-certificates

github
12 месяцев назад

Certifi removes GLOBALTRUST root certificate

EPSS

Процентиль: 83%
0.01928
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-39689