Wind River Support Network

HomeDefectsLIN1023-6956
Fixed

LIN1023-6956 : Security Advisory - python-certifi - CVE-2024-39689

Created: Jul 7, 2024    Updated: May 25, 2025
Resolved Date: May 25, 2025
Found In Version: 10.23.30.1
Fix Version: 10.23.30.13
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.07.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.07.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."

CREATE(Triage):(User=admin) CVE-2024-39689 (https://nvd.nist.gov/vuln/detail/CVE-2024-39689)

CVEs


Live chat
Online