← volver
CVE-2019-14823

CVE-2019-14823

CVSS 6.8 MEDIUMEPSS 0.9%CWE-358
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Productos afectados
Dogtag · JSS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →