CVE Vulnerabilities

CVE-2024-39689

Insufficient Verification of Data Authenticity

Published: Jul 05, 2024 | Modified: Feb 15, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from GLOBALTRUST. Certifi 2024.7.04 removes root certificates from GLOBALTRUST from the root store. These are in the process of being removed from Mozillas trust store. GLOBALTRUSTs root certificates are being removed pursuant to an investigation which identified long-running and unresolved compliance issues.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
CertifiCertifi2021.5.30 (including)2024.7.4 (excluding)
Python-certifiUbuntufocal*
Python-certifiUbuntumantic*
Python-pipUbuntufocal*
Python-pipUbuntumantic*
Python-pipUbuntutrusty/esm*

References