CVE-2023-37920
Certifi's removal of e-Tugra root certificate
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
A flaw was found in the python-certifi package. This issue occurs when the e-Tugra root certificate in Certifi is removed, resulting in an unspecified error that has an unknown impact and attack vector.
An update for fence-agents is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-07-10 CVE Reserved
- 2023-07-25 CVE Published
- 2025-03-05 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 | 2023-08-12 |
URL | Date | SRC |
---|---|---|
https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 | 2023-08-12 | |
https://access.redhat.com/security/cve/CVE-2023-37920 | 2024-10-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2226586 | 2024-10-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kennethreitz Search vendor "Kennethreitz" | Certifi Search vendor "Kennethreitz" for product "Certifi" | >= 2015.04.28 < 2023.07.22 Search vendor "Kennethreitz" for product "Certifi" and version " >= 2015.04.28 < 2023.07.22" | python |
Affected
|