CVE-2024-39689
HIGHCertifi < 2024.7.4 - Data Authenticity Bypass
Title source: ruleDescription
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.2123
EPSS Percentile
95.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-345
Status
published
Products (5)
certifi/certifi
2021.5.30 - 2024.7.4
netapp/management_services_for_element_software_and_netapp_hci
netapp/ontap_select_deploy_administration_utility
netapp/ontap_tools
10
pypi/certifi
2021.5.30 - 2024.7.4PyPI
Published
Jul 05, 2024
Tracked Since
Feb 18, 2026