CVE-2023-37920: Certifi's removal of e-Tugra root certificate
Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.
e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found here.
Other sources
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Certifi's removal of e-Tugra root certificate
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37920?
The severity of CVE-2023-37920 is currently unknown due to an unspecified error regarding the removal of the e-Tugra root certificate in Certifi.
What impact does CVE-2023-37920 have on affected software?
CVE-2023-37920 may lead to unknown impacts and attack vectors related to the removal of the e-Tugra root certificate.
How do I fix CVE-2023-37920?
To remediate CVE-2023-37920, upgrade Certifi to version 2023.07.22 or later.
Which software versions are affected by CVE-2023-37920?
CVE-2023-37920 affects Certifi versions prior to 2023.07.22.
Is my IBM software vulnerable to CVE-2023-37920?
IBM Cognos Dashboards on Cloud Pak for Data versions up to 5.0.0 and 4.8.0 are affected by CVE-2023-37920.