CVE-2022-23491

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*

History

12 Feb 2025, 17:36

Type Values Removed Values Added
CPE cpe:2.3:a:certifi_project:certifi:*:*:*:*:*:*:*:* cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
First Time Certifi
Netapp
Certifi certifi
Netapp e-series Performance Analyzer
Netapp management Services For Element Software
Netapp management Services For Netapp Hci
References () https://security.netapp.com/advisory/ntap-20230223-0010/ - () https://security.netapp.com/advisory/ntap-20230223-0010/ - Third Party Advisory

21 Nov 2024, 06:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.8
References
  • () https://security.netapp.com/advisory/ntap-20230223-0010/ -
References () https://github.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8 - Third Party Advisory () https://github.com/certifi/python-certifi/security/advisories/GHSA-43fp-rhv2-5gv8 - Third Party Advisory
References () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ - Mailing List, Third Party Advisory () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4/m/yLohoVqtCgAJ - Mailing List, Third Party Advisory
Summary
  • (es) Certifi es una colección seleccionada de Root Certificates para validar la confiabilidad de los certificados SSL mientras se verifica la identidad de los hosts TLS. Certifi 2022.12.07 elimina los certificados raíz de "TrustCor" del almacén raíz. Estos están en proceso de ser eliminados del almacén de confianza de Mozilla. Los certificados raíz de TrustCor se están eliminando de conformidad con una investigación impulsada por los medios de comunicación que informaron que la propiedad de TrustCor también operaba un negocio que producía software espía. Las conclusiones de la investigación de Mozilla se pueden encontrar en el grupo de discusión de Google vinculado.

Information

Published : 2022-12-07 22:15

Updated : 2025-02-12 17:36


NVD link : CVE-2022-23491

Mitre link : CVE-2022-23491

CVE.ORG link : CVE-2022-23491


JSON object : View

Products Affected

netapp

  • e-series_performance_analyzer
  • management_services_for_element_software
  • management_services_for_netapp_hci

certifi

  • certifi
CWE
CWE-345

Insufficient Verification of Data Authenticity