JSS: OCSP policy "Leaf and Chain" implicitly trusts the root certificate
Published Oct 14, 2019
7.4
HIGHCVSS 3.1
EPSS 0.86%
Description
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Affected products
-
- Version affects >= 4.4.6StatusaffectedConstraints-
- Version affects >= 4.5.3StatusaffectedConstraints-
- Version affects >= 4.6.0StatusaffectedConstraints-
- Version
Configuration 1
- ≥ 4.4.6 · ≤ 4.4.7
- ≥ 4.5.3 · ≤ 4.5.4
- ≥ 4.6.0 · ≤ 4.6.2
Running on/with
- n/a
Configuration 2
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
- 6.9
- 6.10
- 7.0
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 7.6
- 7.7
- 8.0
Running on/with
- n/a
Configuration 3
- 7.0
- 7.7
- 7.0
- 7.7
- 7.7
- 7.0
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 7
jss-0:4.4.6-3.el7_7
Fixed · RHSA-2019:3067
Red Hat Enterprise Linux 7.6 Extended Update Support
jss-0:4.4.4-6.el7_6
Fixed · RHSA-2019:3225
Red Hat Enterprise Linux 6
jss
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/jss
Not affected
Red Hat Satellite 6
candlepin
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | jss-0:4.4.6-3.el7_7 | Fixed | RHSA-2019:3067 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | jss-0:4.4.4-6.el7_6 | Fixed | RHSA-2019:3225 |
| Red Hat Enterprise Linux 6 | jss | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/jss | Not affected | n/a |
| Red Hat Satellite 6 | candlepin | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Certificate System 9.4 and above use the vulnerable policy. Red Hat Enterprise Satellite 6 does not ship a vulnerable version of the JSS library.
References (10)
- https://access.redhat.com/errata/RHSA-2019:3067 vendor-advisoryx_refsource_REDHATExploitPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3225 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-14823 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1747435 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14823 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENEN4DQBE6WOGEP5BQ5X62WZM7ZQEEBG/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZZWZLNALV6AOIBIHB3ZMNA5AGZMZAIY/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-14823
- https://www.cve.org/CVERecord?id=CVE-2019-14823
Change history (0)
No recorded changes yet.