VDB
CVE-2019-14823
CVE-2019-14823
PUBLISHED
CVSS 6.800000190734863 MEDIUM
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
EPSS 0.86% · 55.7th percentile
Risk Scores
CVSS 3.0
6.800000190734863
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
0.86%
55.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux | 8.0, 6.8, 6.10 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server_tus | 7.7 |
| Dogtag | JSS | affects >= 4.6.0, affects >= 4.5.3, affects >= 4.4.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| jss_cryptomanager_project | jss_cryptomanager | 4.4.6, 4.5.3, 4.6.0 |
| redhat | enterprise_linux_server_aus | 7.7 |
Timeline
- Oct 14, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
References
- FEDORA-2019-68c2fbcf82 vendor-advisory
- FEDORA-2019-4d33c62860 vendor-advisory
- FEDORA-2019-24a0a2f24e vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14823 advisory
- https://access.redhat.com/security/cve/CVE-2019-14823 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1747435 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENEN4DQBE6WOGEP5BQ5X62WZM7ZQEEBG url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZZWZLNALV6AOIBIHB3ZMNA5AGZMZAIY url
- https://access.redhat.com/errata/RHSA-2019:3067 exploit
- https://access.redhat.com/errata/RHSA-2019:3225 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823 issue