CVE-2024-39689

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
Configurations

Configuration 1 (hide)

cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

History

15 Feb 2025, 00:15

Type Values Removed Values Added
Summary (en) Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.07.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues." (en) Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

12 Feb 2025, 20:12

Type Values Removed Values Added
References () https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463 - () https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463 - Patch
References () https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc - () https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc - Vendor Advisory
References () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI - () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI - Mailing List
References () https://security.netapp.com/advisory/ntap-20241206-0001/ - () https://security.netapp.com/advisory/ntap-20241206-0001/ - Third Party Advisory
First Time Certifi
Netapp
Netapp ontap Tools
Certifi certifi
Netapp management Services For Element Software And Netapp Hci
Netapp ontap Select Deploy Administration Utility
CPE cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

06 Dec 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20241206-0001/ -

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463 - () https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463 -
References () https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc - () https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc -
References () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI - () https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI -

08 Jul 2024, 15:49

Type Values Removed Values Added
Summary
  • (es) Certifi es una colección seleccionada de certificados raíz para validar la confiabilidad de los certificados SSL mientras se verifica la identidad de los hosts TLS. Certifi a partir de 2021.05.30 y antes de 2024.07.4 reconoció los certificados raíz de `GLOBALTRUST`. Certifi 2024.07.04 elimina los certificados raíz de `GLOBALTRUST` del almacén raíz. Estos están en proceso de ser eliminados del almacén de confianza de Mozilla. Los certificados raíz de "GLOBALTRUST" se están eliminando tras una investigación que identificó "problemas de cumplimiento de larga duración y no resueltos".

05 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-05 19:15

Updated : 2025-02-15 00:15


NVD link : CVE-2024-39689

Mitre link : CVE-2024-39689

CVE.ORG link : CVE-2024-39689


JSON object : View

Products Affected

certifi

  • certifi

netapp

  • ontap_select_deploy_administration_utility
  • management_services_for_element_software_and_netapp_hci
  • ontap_tools
CWE
CWE-345

Insufficient Verification of Data Authenticity