A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jss_cryptomanager_project jss_cryptomanager |
||
redhat enterprise_linux 6.0 |
||
redhat enterprise_linux 6.1 |
||
redhat enterprise_linux 6.2 |
||
redhat enterprise_linux 6.3 |
||
redhat enterprise_linux 6.4 |
||
redhat enterprise_linux 6.5 |
||
redhat enterprise_linux 6.6 |
||
redhat enterprise_linux 6.7 |
||
redhat enterprise_linux 6.8 |
||
redhat enterprise_linux 6.9 |
||
redhat enterprise_linux 6.10 |
||
redhat enterprise_linux 7.0 |
||
redhat enterprise_linux 7.1 |
||
redhat enterprise_linux 7.2 |
||
redhat enterprise_linux 7.3 |
||
redhat enterprise_linux 7.4 |
||
redhat enterprise_linux 7.5 |
||
redhat enterprise_linux 7.6 |
||
redhat enterprise_linux 7.7 |
||
redhat enterprise_linux 8.0 |
||
redhat enterprise_linux_desktop 7.0 |
||
redhat enterprise_linux_eus 7.7 |
||
redhat enterprise_linux_server 7.0 |
||
redhat enterprise_linux_server_aus 7.7 |
||
redhat enterprise_linux_server_tus 7.7 |
||
redhat enterprise_linux_workstation 7.0 |