← Back

CVE-2019-14823

nvd nist
Published: Oct 14, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Affected (29)

Jss Cryptomanager
7 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
From 4.4.6 to 4.4.7
From 4.5.3 to 4.5.4
From 4.6.0 to 4.6.2
Configuration B
20 vulnerable
Configuration C
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 7.0
Version 7.7
Version 7.0
Version 7.7
Version 7.7
Version 7.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (12)

Source: secalert@redhat.com
ExploitPatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory

Timeline

No history available yet.