cve/2023/CVE-2023-37920.md
2024-05-28 08:49:17 +00:00

23 lines
1.2 KiB
Markdown

### [CVE-2023-37920](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-37920)
![](https://img.shields.io/static/v1?label=Product&message=python-certifi&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3E%3D%202015.04.28%2C%20%3C%202023.07.22%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-345%3A%20Insufficient%20Verification%20of%20Data%20Authenticity&color=brighgreen)
### Description
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Anasdevs/SIH-SBOM-
- https://github.com/HotDB-Community/HotDB-Engine
- https://github.com/PBorocz/manage
- https://github.com/PBorocz/raindrop-io-py
- https://github.com/fokypoky/places-list
- https://github.com/jbugeja/test-repo