CVE-2023-37920

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Configurations

Configuration 1 (hide)

cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*

History

13 Feb 2025, 13:50

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - Mailing List
References () https://security.netapp.com/advisory/ntap-20240912-0002/ - () https://security.netapp.com/advisory/ntap-20240912-0002/ - Third Party Advisory
First Time Netapp
Fedoraproject
Netapp active Iq Unified Manager
Fedoraproject fedora
Netapp ontap Select Deploy Administration Utility
Netapp ontap Mediator
Netapp management Services For Element Software
Netapp solidfire \& Hci Storage Node
Netapp management Services For Netapp Hci

12 Feb 2025, 19:55

Type Values Removed Values Added
First Time Certifi
Certifi certifi
CPE cpe:2.3:a:kennethreitz:certifi:*:*:*:*:*:python:*:* cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

21 Nov 2024, 08:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References
  • () https://security.netapp.com/advisory/ntap-20240912-0002/ -
References () https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - Patch () https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - Patch
References () https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - Vendor Advisory () https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - Vendor Advisory
References () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - Mailing List, Third Party Advisory () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ -

Information

Published : 2023-07-25 21:15

Updated : 2025-02-13 13:50


NVD link : CVE-2023-37920

Mitre link : CVE-2023-37920

CVE.ORG link : CVE-2023-37920


JSON object : View

Products Affected

netapp

  • solidfire_\&_hci_storage_node
  • ontap_select_deploy_administration_utility
  • ontap_mediator
  • management_services_for_element_software
  • active_iq_unified_manager
  • management_services_for_netapp_hci

certifi

  • certifi

fedoraproject

  • fedora
CWE
CWE-345

Insufficient Verification of Data Authenticity