{"id":"CVE-2023-37920","aliases":["GHSA-xqr8-7jwr-rhp7","PYSEC-2023-135"],"url":"https://o3.security/vulnerability/CVE-2023-37920","summary":"Certifi's removal of e-Tugra root certificate","details":"Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes \"e-Tugra\" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from \"e-Tugra\" from the root store.","published":"2023-07-25T20:45:35.286Z","modified":"2026-07-15T01:49:02.228613675Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"certifi","fixedVersion":"2023.7.22"}],"fix":{"url":"https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909","label":"certifi/python-certifi@8fb96ed"},"references":[{"type":"WEB","url":"https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/C-HrP1SEq1A"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EX6NG7WUFNUKGFHLM35KHHU3GAKXRTG/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37920.json"},{"type":"ADVISORY","url":"https://github.com/certifi/python-certifi/security/advisories/GHSA-xqr8-7jwr-rhp7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37920"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240912-0002/"},{"type":"FIX","url":"https://github.com/certifi/python-certifi/commit/8fb96ed81f71e7097ed11bc4d9b19afd7ea5c909"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.228613675Z"}}