7.4
CVSSv3

CVE-2019-14823

Published: 14/10/2019 Updated: 12/02/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jss_cryptomanager_project jss_cryptomanager

redhat enterprise_linux 6.0

redhat enterprise_linux 6.1

redhat enterprise_linux 6.2

redhat enterprise_linux 6.3

redhat enterprise_linux 6.4

redhat enterprise_linux 6.5

redhat enterprise_linux 6.6

redhat enterprise_linux 6.7

redhat enterprise_linux 6.8

redhat enterprise_linux 6.9

redhat enterprise_linux 6.10

redhat enterprise_linux 7.0

redhat enterprise_linux 7.1

redhat enterprise_linux 7.2

redhat enterprise_linux 7.3

redhat enterprise_linux 7.4

redhat enterprise_linux 7.5

redhat enterprise_linux 7.6

redhat enterprise_linux 7.7

redhat enterprise_linux 8.0

redhat enterprise_linux_desktop 7.0

redhat enterprise_linux_eus 7.7

redhat enterprise_linux_server 7.0

redhat enterprise_linux_server_aus 7.7

redhat enterprise_linux_server_tus 7.7

redhat enterprise_linux_workstation 7.0

Vendor Advisories

Debian Bug report logs - #942463 jss: CVE-2019-14823 Package: src:jss; Maintainer for src:jss is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 16 Oct 2019 20:09:02 UTC Severity: grave Tags: security, upstream Found in version jss/46 ...
Synopsis Important: jss security update Type/Severity Security Advisory: Important Topic An update for jss is now available for Red Hat Enterprise Linux 76 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...
Synopsis Important: jss security update Type/Severity Security Advisory: Important Topic An update for jss is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...