CVE-2024-39689

Aliases:GHSA-248v-346w-9cwcPYSEC-2024-230
Modified
Published: 05 Jul 2024, 18:39
Last modified:14 Feb 2025, 23:19

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
26.3% HIGH
26% probability +5.06%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jul 2024, 18:39
Published
Vulnerability first disclosed
14 Feb 2025, 23:19
Last Modified
Vulnerability information updated

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 26.30% Percentile: 96%

Techniques & Countermeasures

  • CWE-345Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Systems

  • certificertifi

    ≥ 2021.5.30, < 2024.7.4

  • certifipython-certifi

    ≥ 2021.5.30, < 2024.7.4

  • netappmanagement_services_for_element_software_and_netapp_hci

    na

  • netappontap_select_deploy_administration_utility

    na

  • netappontap_tools

    10

  • PyPIcertifi

    ≥ 2021.5.30, < 2024.7.4 | < bd8153872e9c6fc98f4023df9c2deaffea2fa463

References (8)