7.4

CVE-2019-14823

Exploit
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jss Cryptomanager Project ≫ Jss Cryptomanager Version >= 4.4.6 <= 4.4.7
   Linux ≫ Linux Kernel Version -
Jss Cryptomanager Project ≫ Jss Cryptomanager Version >= 4.5.3 <= 4.5.4
   Linux ≫ Linux Kernel Version -
Jss Cryptomanager Project ≫ Jss Cryptomanager Version >= 4.6.0 <= 4.6.2
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.0
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.1
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.2
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.3
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.4
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.5
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.6
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.7
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.8
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.9
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 6.10
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.0
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.1
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.2
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.3
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.4
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.5
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.6
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 7.7
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Version 8.0
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Desktop Version 7.0 HwPlatform x64
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Eus Version 7.7
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Server Version 7.0
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Server Aus Version 7.7
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Server Tus Version 7.7
   Linux ≫ Linux Kernel Version -
Redhat ≫ Enterprise Linux Workstation Version 7.0 HwPlatform x64
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat 6.8 1.6 5.2
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

CWE-358 Improperly Implemented Security Check for Standard

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

https://access.redhat.com/errata/RHSA-2019:3067
Patch
Third Party Advisory
Exploit
https://access.redhat.com/errata/RHSA-2019:3225
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823
Patch
Third Party Advisory
Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENEN4DQBE6WOGEP5BQ5X62WZM7ZQEEBG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZZWZLNALV6AOIBIHB3ZMNA5AGZMZAIY/