CVE-2023-37920: Certifi
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Affected products
- Certifi Certifi: from 2015.4.28, before 2023.7.22 (fixed in 2023.7.22)
- Fedoraproject Fedora: version 38 only
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Management Services For Element Software: affected versions not specified
- Netapp Management Services For Netapp Hci: affected versions not specified
- Netapp Ontap Mediator: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Solidfire & Hci Storage Node: affected versions not specified
Published 2023-07-25. Last modified 2026-06-17.