Bug 1227519 (CVE-2024-39689) - VUL-0: CVE-2024-39689: python-certifi: remove root certificates from `GLOBALTRUST` from the root store
Summary: VUL-0: CVE-2024-39689: python-certifi: remove root certificates from `GLOBALT...
Status: RESOLVED FIXED
Alias: CVE-2024-39689
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/412941/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-39689:3.7:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-08 14:01 UTC by SMASH SMASH
Modified: 2024-07-09 08:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-07-08 14:01:54 UTC
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.07.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-39689
https://www.cve.org/CVERecord?id=CVE-2024-39689
https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463
https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI
https://bugzilla.redhat.com/show_bug.cgi?id=2296020
Comment 2 Daniel Garcia 2024-07-09 07:28:35 UTC
This issue doesn't affect our package because these packages uses the certificates from the system (/etc/ssl/ca-bundle.pem). The cacert.pem provided by upstream is removed from the final package.

So these codestreams are not affected:
 - SUSE:ALP:Source:Standard:1.0/python-certifi
 - SUSE:SLE-15-SP4:Update/python-certifi

I've created an update request for Factory and SLFO, even when these packages are not affected either.
Comment 3 OBSbugzilla Bot 2024-07-09 07:55:04 UTC
This is an autogenerated message for OBS integration:
This bug (1227519) was mentioned in
https://build.opensuse.org/request/show/1186314 Factory / python-certifi
Comment 5 Andrea Mattiazzo 2024-07-09 08:21:34 UTC
All done, closing.