← Vulnerability feed

Vulnerability record · CVE-2022-23491 · published 7 December 2022

CVE-2022-23491: Certifi insufficient verification of data authenticity vulnerability

Certifi · Certifi

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

7.5 CVSS 3.1 High EPSS 0.51% · top 58.6% CWE-345 · Insufficient verification of data authenticity
7.5CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found in the linked google group discussion.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23491 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2023-37920Certifi insufficient verification of data authenticity vulnerabilityCertifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts…EPSS 0.57%9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 19%9.8CVE-2021-26707Merge-deep project merge-deep prototype pollution vulnerabilityThe merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These …EPSS 1.9%9.8CVE-2021-23383Handlebarsjs handlebars prototype pollution vulnerabilityThe package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from a…EPSS 4.5%9.8CVE-2021-20231Gnutls use after free vulnerabilityA flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.EPSS 3.8%8.8CVE-2022-21703Grafana cross-site request forgery vulnerabilityGrafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…EPSS 2.3%8.8CVE-2021-32762Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to in…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2022-23491), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.