VDB
CVE-2019-14823
CVE-2019-14823
PUBLISHED
CVSS 6.800000190734863 MEDIUM
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
EPSS 0.29% · 52.5th percentile
Risk Scores
CVSS 3.0
6.800000190734863
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
0.29%
52.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux | 8.0, 6.8, 6.10 |
| redhat | enterprise_linux_eus | 7.7 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server_tus | 7.7 |
| Dogtag | JSS | affects >= 4.6.0, affects >= 4.5.3, affects >= 4.4.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| jss_cryptomanager_project | jss_cryptomanager | 4.4.6, 4.5.3, 4.6.0 |
| redhat | enterprise_linux_server_aus | 7.7 |
Exploit Intelligence
- https://access.redhat.com/errata/RHSA-2019:3067 (nist-nvd)
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823 (circl)
- FEDORA-2019-68c2fbcf82 (circl)
- FEDORA-2019-4d33c62860 (circl)
- FEDORA-2019-24a0a2f24e (circl)
- RHSA-2019:3225 (circl)
Timeline
- Oct 14, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823 url
- RHSA-2019:3067 vendor-advisory
- FEDORA-2019-68c2fbcf82 vendor-advisory
- FEDORA-2019-4d33c62860 vendor-advisory
- FEDORA-2019-24a0a2f24e vendor-advisory
- RHSA-2019:3225 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-14823 advisory
- https://access.redhat.com/security/cve/CVE-2019-14823 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1747435 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENEN4DQBE6WOGEP5BQ5X62WZM7ZQEEBG url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZZWZLNALV6AOIBIHB3ZMNA5AGZMZAIY url