Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-23491 Details

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-345Insufficient Verification of Data Authenticity[email protected]
CWE-345Insufficient Verification of Data Authenticity[email protected]

Affected Products

ProductVersions
certifi certifi
>= 2017.11.5, < 2022.12.7

CPE

  • cpe:2.3:a:certifi:certifi:*:*:*:*:*:python:*:*

Remediation

  • No remediation found in references.
netapp e-series performance analyzer
All versions

CPE

  • cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
netapp management services for element software
All versions

CPE

  • cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
netapp management services for netapp hci
All versions

CPE

  • cpe:2.3:a:netapp:management_services_for_netapp_hci:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-23491
NVD Published Date:
Dec 7, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-23491 Details - Not Deferred