A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2019-10-14T19:35:04
Updated: 2019-10-29T16:06:22
Reserved: 2019-08-10T00:00:00
Link: CVE-2019-14823
JSON object: View
NVD Information
Status : Modified
Published: 2019-10-14T20:15:10.540
Modified: 2023-02-12T23:34:06.883
Link: CVE-2019-14823
JSON object: View
Redhat Information
No data.