#VU79296 Insufficient verification of data authenticity in python-certifi - CVE-2023-37920
Published: August 9, 2023 / Updated: December 4, 2024
python-certifi
Certifi
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exist due to software recognizes "e-Tugra" root certificates, which were subject to an investigation prompted by reporting of security issues in their systems. An attacker with ability to generate certificates signed with the compromised "e-Tugra" root certificate can perform MitM attack.