Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

node/deps/uv/docs/requirements.txt certifi@2022.12.7 is vulnerable to CVE-2023-37920 #188

Closed
tahabiyikli opened this issue Jul 10, 2024 · 1 comment

Comments

@tahabiyikli
Copy link

Affected versions of this package are vulnerable to Improper Following of a Certificate's Chain of Trust. E-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found here.

CVE-2023-37920 ref: opensearch-project/data-prepper#3070

image

Vulnerability ID: https://nvd.nist.gov/vuln/detail/CVE-2023-37920
Failed run: https://github.com/nodejs/node/blob/main/deps/uv/docs/requirements.txt

@richardlau
Copy link
Member

FWIW libuv do not consider this a vulnerability: libuv/libuv#4389

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants