CVE-2024-39689

HIGH

Certifi < 2024.7.4 - Data Authenticity Bypass

Title source: rule

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

Exploits (1)

nomisec STUB
by roy-aladin · poc
https://github.com/roy-aladin/InfraTest

Scores

CVSS v3 7.5
EPSS 0.2123
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-345
Status published
Products (5)
certifi/certifi 2021.5.30 - 2024.7.4
netapp/management_services_for_element_software_and_netapp_hci
netapp/ontap_select_deploy_administration_utility
netapp/ontap_tools 10
pypi/certifi 2021.5.30 - 2024.7.4PyPI
Published Jul 05, 2024
Tracked Since Feb 18, 2026