A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- CVSS 3.0 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade jss-javadocUpgrade jss-debuginfoUpgrade jss | Oct 16, 2019 | Oct 14, 2019 |
| Debian | — | Upgrade jss | Jul 30, 2024 | Oct 14, 2019 |
| Oracle_linux | — | Upgrade jssUpgrade jss-javadoc | Oct 5, 2022 | Oct 14, 2019 |
| Redhat_linux | — | Upgrade jssUpgrade jss-javadocUpgrade jss-debuginfo | Oct 16, 2019 | Oct 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub