IT

Tracker / CVE-2019-14823

CVE-2019-14823

High 7.4

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Affected products and versions

jss_cryptomanager_project jss_cryptomanager · 4.4.6 → 4.4.7
jss_cryptomanager_project jss_cryptomanager · 4.5.3 → 4.5.4
jss_cryptomanager_project jss_cryptomanager · 4.6.0 → 4.6.2
redhat enterprise_linux
redhat enterprise_linux_desktop
redhat enterprise_linux_eus
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_tus
redhat enterprise_linux_workstation

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References