Appsecure logo

CVE-2024-39689: High Vulnerability in Certifi

A high-severity vulnerability found in Certifi could lead to significant integrity impacts due to improper handling of root certificates. Organizations using affected versions should prioritize remediation to maintain secure TLS connections.

HIGHPublic ExploitCVSS 7.5 · Published July 5, 2024

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2024-39689 is a high-severity vulnerability affecting Certifi, a curated collection of root certificates used for validating SSL certificates. The vulnerability arises from the recognition of root certificates from `GLOBALTRUST`, which have been associated with unresolved compliance issues. As of version 2024.7.4, Certifi has removed these certificates from its root store, aligning with Mozilla's ongoing removal process. This change highlights the importance of maintaining proper certificate trust chains to prevent potential exploitation.

The CVSS score for this vulnerability is 7.5, indicating a high level of severity. This score emphasizes the urgency for organizations to address the issue, as failure to do so could lead to significant integrity impacts. Attackers may leverage this vulnerability to compromise the integrity of data transmitted over TLS connections, potentially leading to unauthorized modifications.

Given the nature of this vulnerability and its potential impact, organizations should prioritize patching immediately. The exploitability of this vulnerability is high, and as such, it is critical to act swiftly to mitigate associated risks.

Organizations utilizing affected components such as Certifi and various NetApp products must ensure they have upgraded to the latest versions to eliminate the risks posed by this vulnerability.

For more detailed technical information and remediation steps, refer to the relevant advisories and patches provided by the vendor.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.