PT-2019-13851 · Jss+3 · Cryptomanager+3
Alexander Scheel
+1
·
Published
2019-10-14
·
Updated
2023-02-12
·
CVE-2019-14823
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0
Description
A flaw was found in the "Leaf and Chain" OCSP policy implementation where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Recommendations
For JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, consider disabling the "Leaf and Chain" OCSP policy until a patch is available to prevent implicit trust of the root certificate.
Restrict access to applications using this policy to minimize the risk of exploitation.
Avoid using the affected CryptoManager versions in sensitive environments until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improperly Implemented Security Check for Standard
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Cryptomanager
Red Hat