5.8
CVSSv2

CVE-2019-14823

Published: 14/10/2019 Updated: 12/02/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jss cryptomanager project jss cryptomanager

redhat enterprise linux 6.0

redhat enterprise linux 6.1

redhat enterprise linux 6.2

redhat enterprise linux 6.3

redhat enterprise linux 6.4

redhat enterprise linux 6.5

redhat enterprise linux 6.6

redhat enterprise linux 6.7

redhat enterprise linux 6.8

redhat enterprise linux 6.9

redhat enterprise linux 6.10

redhat enterprise linux 7.0

redhat enterprise linux 7.1

redhat enterprise linux 7.2

redhat enterprise linux 7.3

redhat enterprise linux 7.4

redhat enterprise linux 7.5

redhat enterprise linux 7.6

redhat enterprise linux 7.7

redhat enterprise linux 8.0

redhat enterprise linux desktop 7.0

redhat enterprise linux eus 7.7

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.7

redhat enterprise linux server tus 7.7

redhat enterprise linux workstation 7.0

Vendor Advisories

Synopsis Important: jss security update Type/Severity Security Advisory: Important Topic An update for jss is now available for Red Hat Enterprise Linux 76 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...
Synopsis Important: jss security update Type/Severity Security Advisory: Important Topic An update for jss is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which g ...
Debian Bug report logs - #942463 jss: CVE-2019-14823 Package: src:jss; Maintainer for src:jss is Debian FreeIPA Team <pkg-freeipa-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 16 Oct 2019 20:09:02 UTC Severity: grave Tags: security, upstream Found in version jss/46 ...