CVE-2022-23491
Summary
| CVE | CVE-2022-23491 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-07 22:15:00 UTC |
| Updated | 2023-03-24 18:12:00 UTC |
| Description | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Removal of TrustCor root certificate · Advisory · certifi/python-certifi · GitHub |
MISC |
github.com |
|
| concerns about Trustcor |
MISC |
groups.google.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150735 Oracle WebLogic Server Multiple Vulnerabilities (CPU - OCT2023)
- 199432 Ubuntu Security Notification for Ca-certificates Update (USN-5761-1)
- 20366 Oracle Database 19c Critical Patch Update - October 2023
- 20367 Oracle Database 21c Critical Patch Update - October 2023
- 20368 Oracle Database 19c Critical OJVM Patch Update - October 2023
- 283832 Fedora Security Update for mingw (FEDORA-2023-7ed04fe4a7)
- 283833 Fedora Security Update for mingw (FEDORA-2023-ed525aa807)
- 284233 Fedora Security Update for mingw (FEDORA-2023-bc1545f9bc)
- 354746 Amazon Linux Security Advisory for ca-certificates : ALAS-2023-1690
- 354778 Amazon Linux Security Advisory for ca-certificates : ALAS2-2023-1957
- 355150 Amazon Linux Security Advisory for ca-certificates : ALAS2023-2023-061
- 355282 Amazon Linux Security Advisory for python-certifi : ALAS2023-2023-062
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 753542 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2023:0119-1)
- 753547 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2023:0118-1)
- 753559 SUSE Enterprise Linux Security Update for mozilla-nss (SUSE-SU-2023:0130-1)
- 753561 SUSE Enterprise Linux Security Update for python-certifi (SUSE-SU-2023:0139-1)
- 87548 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2023)