First published: Fri Jul 05 2024(Updated: )
Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store. GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found [here]( https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI).
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/certifi | >=2021.5.30<2024.7.4 | 2024.7.4 |
Certifi | >=2021.5.30<2024.7.4 | |
NetApp Management Services for NetApp HCI | ||
NetApp ONTAP Select Deploy | ||
netapp ontap tools vmware vsphere | =10 | |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39689 has been classified as a moderate severity vulnerability due to its potential impact on trust in root certificates.
To fix CVE-2024-39689, upgrade to Certifi version 2024.07.04 or later.
CVE-2024-39689 affects the Certifi package versions between 2021.05.30 and 2024.07.04, as well as certain NetApp software.
The implications of CVE-2024-39689 primarily involve the removal of GLOBALTRUST root certificates from the trust store, potentially affecting secure communications.
CVE-2024-39689 was caused by an investigation revealing long-standing issues with the GLOBALTRUST root certificates.