OESA-2023-1457

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1457
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1457.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1457
Upstream
Published
2023-08-06T11:05:36Z
Modified
2025-08-12T05:12:36.383917Z
Summary
python-certifi security update
Details

Certifi provides Mozilla carefully curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. It has been extracted from the Requests project

Security Fix(es):

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.(CVE-2022-23491)

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.(CVE-2023-37920)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-certifi

Package

Name
python-certifi
Purl
pkg:rpm/openEuler/python-certifi&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2023.7.22-1.oe1

Ecosystem specific

{
    "src": [
        "python-certifi-2023.7.22-1.oe1.src.rpm"
    ],
    "noarch": [
        "python-certifi-help-2023.7.22-1.oe1.noarch.rpm",
        "python3-certifi-2023.7.22-1.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / python-certifi

Package

Name
python-certifi
Purl
pkg:rpm/openEuler/python-certifi&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2023.7.22-1.oe1

Ecosystem specific

{
    "src": [
        "python-certifi-2023.7.22-1.oe1.src.rpm"
    ],
    "noarch": [
        "python-certifi-help-2023.7.22-1.oe1.noarch.rpm",
        "python3-certifi-2023.7.22-1.oe1.noarch.rpm"
    ]
}

openEuler:22.03-LTS / python-certifi

Package

Name
python-certifi
Purl
pkg:rpm/openEuler/python-certifi&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2023.7.22-1.oe2203sp2

Ecosystem specific

{
    "src": [
        "python-certifi-2023.7.22-1.oe2203.src.rpm",
        "python-certifi-2023.7.22-1.oe2203sp1.src.rpm",
        "python-certifi-2023.7.22-1.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "python-certifi-help-2023.7.22-1.oe2203.noarch.rpm",
        "python3-certifi-2023.7.22-1.oe2203.noarch.rpm",
        "python3-certifi-2023.7.22-1.oe2203sp1.noarch.rpm",
        "python-certifi-help-2023.7.22-1.oe2203sp1.noarch.rpm",
        "python3-certifi-2023.7.22-1.oe2203sp2.noarch.rpm",
        "python-certifi-help-2023.7.22-1.oe2203sp2.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / python-certifi

Package

Name
python-certifi
Purl
pkg:rpm/openEuler/python-certifi&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2023.7.22-1.oe2203sp1

Ecosystem specific

{
    "src": [
        "python-certifi-2023.7.22-1.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "python3-certifi-2023.7.22-1.oe2203sp1.noarch.rpm",
        "python-certifi-help-2023.7.22-1.oe2203sp1.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / python-certifi

Package

Name
python-certifi
Purl
pkg:rpm/openEuler/python-certifi&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2023.7.22-1.oe2203sp2

Ecosystem specific

{
    "src": [
        "python-certifi-2023.7.22-1.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "python3-certifi-2023.7.22-1.oe2203sp2.noarch.rpm",
        "python-certifi-help-2023.7.22-1.oe2203sp2.noarch.rpm"
    ]
}