ALT-PU-2019-3187-1
Closed vulnerabilities
Published: 2019-10-14
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14823
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Severity: HIGH (7.4)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
- RHSA-2019:3067
- RHSA-2019:3067
- RHSA-2019:3225
- RHSA-2019:3225
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823
- FEDORA-2019-24a0a2f24e
- FEDORA-2019-24a0a2f24e
- FEDORA-2019-68c2fbcf82
- FEDORA-2019-68c2fbcf82
- FEDORA-2019-4d33c62860
- FEDORA-2019-4d33c62860