Description
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Published: 2023-07-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-0052 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Github GHSA Github GHSA GHSA-xqr8-7jwr-rhp7 Removal of e-Tugra root certificate
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00115}

epss

{'score': 0.00112}


Wed, 05 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Fedoraproject
Fedoraproject fedora
Netapp
Netapp active Iq Unified Manager
Netapp management Services For Element Software
Netapp management Services For Netapp Hci
Netapp ontap Mediator
Netapp ontap Select Deploy Administration Utility
Netapp solidfire \& Hci Storage Node
CPEs cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_mediator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Vendors & Products Fedoraproject
Fedoraproject fedora
Netapp
Netapp active Iq Unified Manager
Netapp management Services For Element Software
Netapp management Services For Netapp Hci
Netapp ontap Mediator
Netapp ontap Select Deploy Administration Utility
Netapp solidfire \& Hci Storage Node

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Certifi
Certifi certifi
CPEs cpe:2.3:a:kennethreitz:certifi:*:*:*:*:*:python:*:* cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*
Vendors & Products Kennethreitz
Kennethreitz certifi
Certifi
Certifi certifi

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 23 Oct 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:openshift:4.17::el9
Vendors & Products Redhat openshift

Thu, 17 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9

Subscriptions

Certifi Certifi
Fedoraproject Fedora
Netapp Active Iq Unified Manager Management Services For Element Software Management Services For Netapp Hci Ontap Mediator Ontap Select Deploy Administration Utility Solidfire \& Hci Storage Node
Redhat Enterprise Linux Openshift Rhel Aus Rhel E4s Rhel Eus Rhel Tus
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-05T18:47:15.819Z

Reserved: 2023-07-10T17:51:29.612Z

Link: CVE-2023-37920

cve-icon Vulnrichment

Updated: 2024-09-12T16:02:55.011Z

cve-icon NVD

Status : Analyzed

Published: 2023-07-25T21:15:10.827

Modified: 2025-02-13T13:50:15.813

Link: CVE-2023-37920

cve-icon Redhat

Severity : Low

Publid Date: 2023-07-25T00:00:00Z

Links: CVE-2023-37920 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses