CVE-2023-37920

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Configurations

Configuration 1 (hide)

cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*

History

13 Feb 2025, 13:50

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - Mailing List
References () https://security.netapp.com/advisory/ntap-20240912-0002/ - () https://security.netapp.com/advisory/ntap-20240912-0002/ - Third Party Advisory
First Time Netapp
Fedoraproject fedora
Netapp ontap Select Deploy Administration Utility
Fedoraproject
Netapp management Services For Netapp Hci
Netapp management Services For Element Software
Netapp active Iq Unified Manager
Netapp ontap Mediator
Netapp solidfire \& Hci Storage Node

12 Feb 2025, 19:55

Type Values Removed Values Added
First Time Certifi
Certifi certifi
CPE cpe:2.3:a:kennethreitz:certifi:*:*:*:*:*:python:*:* cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

21 Nov 2024, 08:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References
  • () https://security.netapp.com/advisory/ntap-20240912-0002/ -
References () https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - Patch () https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - Patch
References () https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - Vendor Advisory () https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - Vendor Advisory
References () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - Mailing List, Third Party Advisory () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ -

12 Aug 2023, 06:16

Type Values Removed Values Added
References
  • (MISC) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/ -

03 Aug 2023, 16:19

Type Values Removed Values Added
CPE cpe:2.3:a:kennethreitz:certifi:*:*:*:*:*:python:*:*
References (MISC) https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - (MISC) https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7 - Vendor Advisory
References (MISC) https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - (MISC) https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A - Mailing List, Third Party Advisory
References (MISC) https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - (MISC) https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909 - Patch
First Time Kennethreitz certifi
Kennethreitz
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

25 Jul 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-25 21:15

Updated : 2025-02-13 13:50


NVD link : CVE-2023-37920

Mitre link : CVE-2023-37920

CVE.ORG link : CVE-2023-37920


JSON object : View

Products Affected

netapp

  • ontap_mediator
  • solidfire_\&_hci_storage_node
  • active_iq_unified_manager
  • management_services_for_netapp_hci
  • management_services_for_element_software
  • ontap_select_deploy_administration_utility

fedoraproject

  • fedora

certifi

  • certifi
CWE
CWE-345

Insufficient Verification of Data Authenticity