7.4

CVE-2019-14823

Exploit

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Data is provided by the National Vulnerability Database (NVD)
Jss Cryptomanager ProjectJss Cryptomanager Version >= 4.4.6 <= 4.4.7
   LinuxLinux Kernel Version-
Jss Cryptomanager ProjectJss Cryptomanager Version >= 4.5.3 <= 4.5.4
   LinuxLinux Kernel Version-
Jss Cryptomanager ProjectJss Cryptomanager Version >= 4.6.0 <= 4.6.2
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.0
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.1
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.2
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.3
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.4
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.5
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.6
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.7
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.8
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.9
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version6.10
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.0
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.1
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.2
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.3
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.4
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.5
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.6
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version7.7
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Version8.0
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Desktop Version7.0 HwPlatformx64
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Eus Version7.7
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Server Version7.0
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Server Aus Version7.7
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Server Tus Version7.7
   LinuxLinux Kernel Version-
RedhatEnterprise Linux Workstation Version7.0 HwPlatformx64
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.518
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
secalert@redhat.com 6.8 1.6 5.2
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

CWE-358 Improperly Implemented Security Check for Standard

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.