CVE Vulnerabilities

CVE-2024-39689

Insufficient Verification of Data Authenticity

Published: Jul 05, 2024 | Modified: Jul 08, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
NEGLIGIBLE

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from GLOBALTRUST. Certifi 2024.07.04 removes root certificates from GLOBALTRUST from the root store. These are in the process of being removed from Mozillas trust store. GLOBALTRUSTs root certificates are being removed pursuant to an investigation which identified long-running and unresolved compliance issues.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Python-certifi Ubuntu devel *
Python-certifi Ubuntu esm-apps/xenial *
Python-certifi Ubuntu esm-infra/bionic *
Python-certifi Ubuntu focal *
Python-certifi Ubuntu jammy *
Python-certifi Ubuntu mantic *
Python-certifi Ubuntu noble *
Python-pip Ubuntu devel *
Python-pip Ubuntu esm-apps/bionic *
Python-pip Ubuntu esm-apps/focal *
Python-pip Ubuntu esm-apps/jammy *
Python-pip Ubuntu esm-apps/noble *
Python-pip Ubuntu esm-apps/xenial *
Python-pip Ubuntu esm-infra-legacy/trusty *
Python-pip Ubuntu focal *
Python-pip Ubuntu jammy *
Python-pip Ubuntu mantic *
Python-pip Ubuntu noble *
Python-pip Ubuntu trusty/esm *

References