Bug 6854 - [Anolis OS 23] Bugfix for CVE-2022-23491
Summary: [Anolis OS 23] Bugfix for CVE-2022-23491
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-10-17 11:36 UTC by 小龙
Modified: 2023-10-17 11:37 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-10-17 11:36:57 UTC
Description:
Certifi是根证书的精选集合,用于验证SSL证书的可信度,同时验证TLS主机的身份。Certifi2022.12.07从根存储中的TrustCor中删除根证书。这些正在从Mozilla的信任存储中删除。根据媒体报道,TrustCor的所有权还经营一家生产间谍软件的企业,调查促使TrustCor的根证书被删除。Mozilla调查的结论可以在链接的谷歌小组讨论中找到。

Broken commit info:

Bugfix commit info:
https://github.com/certifi/python-certifi/commit/9e9e840925d7b8e76c76fdac1fab7e6e88c1c3b8