First published: Tue Jul 25 2023(Updated: )
An unspecified error with the removal of e-Tugra root certificate in Certifi has an unknown impact and attack vector.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/certifi | <2023.07.22 | 2023.07.22 |
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
certifi | >=2015.04.28<2023.07.22 | |
pip/certifi | >=2015.4.28<2023.7.22 | 2023.7.22 |
Certifi | >=2015.4.28<2023.7.22 | |
Fedora | =38 | |
netapp active iq unified manager vsphere | ||
netapp active iq unified manager windows | ||
netapp management services for element software | ||
NetApp Management Services for NetApp HCI | ||
Netapp Ontap Mediator | ||
NetApp ONTAP Select Deploy | ||
netapp solidfire \& hci storage node |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37920 is currently unknown due to an unspecified error regarding the removal of the e-Tugra root certificate in Certifi.
CVE-2023-37920 may lead to unknown impacts and attack vectors related to the removal of the e-Tugra root certificate.
To remediate CVE-2023-37920, upgrade Certifi to version 2023.07.22 or later.
CVE-2023-37920 affects Certifi versions prior to 2023.07.22.
IBM Cognos Dashboards on Cloud Pak for Data versions up to 5.0.0 and 4.8.0 are affected by CVE-2023-37920.