Insufficient Verification of Data Authenticity Affecting python-certifi package, versions <2024.8.30-1


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.05% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-PYTHONCERTIFI-7426201
  • published6 Jul 2024
  • disclosed5 Jul 2024

Introduced: 5 Jul 2024

CVE-2024-39689  (opens in a new tab)
CWE-345  (opens in a new tab)

How to fix?

Upgrade Debian:13 python-certifi to version 2024.8.30-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-certifi package and not the python-certifi package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from GLOBALTRUST. Certifi 2024.07.04 removes root certificates from GLOBALTRUST from the root store. These are in the process of being removed from Mozilla's trust store. GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

CVSS Scores

version 3.1