CVE-2023-32803
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-669
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- n/a n/a
- Amazon ca-certificates
Weakness type
Related vulnerabilities
- CVE-2025-41660 — CODESYS Control Boot Application Replacement Enables Code Execution
- CVE-2026-25253 — OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
- CVE-2025-41645 — SMA: Sunny Portal demo system privilege escalation
- CVE-2025-34158 — Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spher
- CVE-2025-67895 — Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2
- CVE-2022-30236 — A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an
- CVE-2025-62775 — Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
- CVE-2024-38519 — yt-dlp and youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization