U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-39689

Change History

New CVE Received from GitHub, Inc. 7/05/2024 3:15:10 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.07.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Added CWE

								
							
							
						
GitHub, Inc. CWE-345
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI [No types assigned]