CyberRota Analysis
AI-GeneratedThe ca-certificates package in Amazon Linux 2 prior to version 2021.2.50-72 contains unremoved TrustCor root certificates, potentially allowing unauthorized access or man-in-the-middle attacks due to improper certificate validation. Organizations using Amazon Linux 2 should prioritize patching this vulnerability to mitigate risks associated with compromised trust in certificate authorities.
CVE
CVE-2023-32803
Severity
HIGH
CVSS
7.5
EPSS
0.18%
Linux
Original NVD Description
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.