Lucene search

K
nvd[email protected]NVD:CVE-2022-23491
HistoryDec 07, 2022 - 10:15 p.m.

CVE-2022-23491

2022-12-0722:15:09
CWE-345
web.nvd.nist.gov
8
certifi
root certificates
ssl certificates
tls hosts
trustcor
mozilla
investigation
spyware
google group

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

23.8%

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from “TrustCor” from the root store. These are in the process of being removed from Mozilla’s trust store. TrustCor’s root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor’s ownership also operated a business that produced spyware. Conclusions of Mozilla’s investigation can be found in the linked google group discussion.

Affected configurations

Nvd
Node
certifi_projectcertifiRange2017.11.52022.12.7
VendorProductVersionCPE
certifi_projectcertifi*cpe:2.3:a:certifi_project:certifi:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

23.8%