CPANSA-Mozilla-CA-2024-39689: Mozilla-CA vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2024-06-11T00:00:00 Engine CSAF Perl Toolkit 0.25
Current release date 2024-06-11T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score 7.5 Severity Low
Original language Language en
Also referred to

Vulnerability Description

ECM GlobalTrust 2000 root certificates have been distrusted

Vulnerabilities

CVE-2024-39689

Vulnerability Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

Weakness CWE-345 : Insufficient Verification of Data Authenticity

Product status

Known affected
Product Score
Mozilla-CA less than 20240730
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 7.5 High
Fixed

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Tue Jun 11 00:00:00 2024 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/