-
Notifications
You must be signed in to change notification settings - Fork 214
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-39689 (High) detected in certifi-2023.7.22-py3-none-any.whl #4715
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
Milestone
Comments
mend-for-github-com
bot
added
the
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
label
Jul 9, 2024
dlvenable
added a commit
to dlvenable/data-prepper
that referenced
this issue
Jul 12, 2024
…-project#4715, opensearch-project#4713, 4714. Signed-off-by: David Venable <dlv@amazon.com>
4 tasks
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Jul 23, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Jul 23, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Jul 30, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Aug 8, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Aug 12, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
kkondaka
pushed a commit
to kkondaka/kk-data-prepper-f2
that referenced
this issue
Aug 14, 2024
…-project#4715, opensearch-project#4713, 4714. (opensearch-project#4733) Signed-off-by: David Venable <dlv@amazon.com> Signed-off-by: Krishna Kondaka <krishkdk@dev-dsk-krishkdk-2c-bd29c437.us-west-2.amazon.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
CVE-2024-39689 - High Severity Vulnerability
Vulnerable Library - certifi-2023.7.22-py3-none-any.whl
Python package for providing Mozilla's CA Bundle.
Library home page: https://files.pythonhosted.org/packages/4c/dd/2234eab22353ffc7d94e8d13177aaa050113286e93e7b40eae01fbf7c3d9/certifi-2023.7.22-py3-none-any.whl
Path to dependency file: /release/smoke-tests/otel-span-exporter/requirements.txt
Path to vulnerable library: /release/smoke-tests/otel-span-exporter/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 90bdaa7e7833bdd504c817e49d4434b4d8880f56
Found in base branch: main
Vulnerability Details
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from
GLOBALTRUST
. Certifi 2024.07.04 removes root certificates fromGLOBALTRUST
from the root store. These are in the process of being removed from Mozilla's trust store.GLOBALTRUST
's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."Publish Date: 2024-07-05
URL: CVE-2024-39689
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-248v-346w-9cwc
Release Date: 2024-07-05
Fix Resolution: certifi - 2024.07.04
The text was updated successfully, but these errors were encountered: