A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
{
"versions": [
{
"introduced": "4.4.6"
},
{
"last_affected": "4.4.7"
},
{
"introduced": "4.5.3"
},
{
"last_affected": "4.5.4"
},
{
"introduced": "4.6.0"
},
{
"last_affected": "4.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "6.2"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.2"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14823.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.7"
}
]
}
]