CVE-2023-37920: Alpine 3.18 with Node.js 20 needs to update certifi dependent libraries
The certifi package is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
This means that Alpine 3.18, which uses certifi version 2023.07.18, is vulnerable to the CVE-2023-37920 vulnerability. To fix this vulnerability, the following certifi dependent libraries need to be updated to the latest version:
ca-certificates certifi libssl1.1
I suggest that the Alpine team update the affected packages as soon as possible to mitigate this vulnerability.
I hope this is helpful!