Skip to content

Removal of GLOBALTRUST root certificate

Low
alex published GHSA-248v-346w-9cwc Jul 4, 2024

Package

pip certifi (pip)

Affected versions

>=2021.05.30,<2024.07.04

Patched versions

>=2024.07.04

Description

Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store.

GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found here.

Severity

Low

CVE ID

CVE-2024-39689

Weaknesses

No CWEs