CVE-2019-14823

HIGH

JSS CryptoManager >4.4.6-4.6.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Scores

CVSS v3 7.4
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295 CWE-358
Status published
Products (27)
jss_cryptomanager_project/jss_cryptomanager 4.4.6 - 4.4.7
redhat/enterprise_linux 6.0
redhat/enterprise_linux 6.1
redhat/enterprise_linux 6.2
redhat/enterprise_linux 6.3
redhat/enterprise_linux 6.4
redhat/enterprise_linux 6.5
redhat/enterprise_linux 6.6
redhat/enterprise_linux 6.7
redhat/enterprise_linux 6.8
... and 17 more
Published Oct 14, 2019
Tracked Since Feb 18, 2026