Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-14823
Description:A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Test IDs: 1.3.6.1.4.1.25623.1.0.883116   1.3.6.1.4.1.25623.1.0.876933   1.3.6.1.4.1.25623.1.0.876947   1.3.6.1.4.1.25623.1.1.10.2020.0018   1.3.6.1.4.1.25623.1.0.877200  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-14823
FEDORA-2019-24a0a2f24e
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENEN4DQBE6WOGEP5BQ5X62WZM7ZQEEBG/
FEDORA-2019-4d33c62860
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZZWZLNALV6AOIBIHB3ZMNA5AGZMZAIY/
FEDORA-2019-68c2fbcf82
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/
RHSA-2019:3067
https://access.redhat.com/errata/RHSA-2019:3067
RHSA-2019:3225
https://access.redhat.com/errata/RHSA-2019:3225
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823




© 1998-2025 E-Soft Inc. All rights reserved.