A flaw was found in the Leaf and Chain OCSP policy implementation in JSS CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jss_cryptomanager | Jss_cryptomanager_project | 4.4.6 (including) | 4.4.7 (including) |
Jss_cryptomanager | Jss_cryptomanager_project | 4.5.3 (including) | 4.5.4 (including) |
Jss_cryptomanager | Jss_cryptomanager_project | 4.6.0 (including) | 4.6.2 (including) |
Red Hat Enterprise Linux 7 | RedHat | jss-0:4.4.6-3.el7_7 | * |
Red Hat Enterprise Linux 7.6 Extended Update Support | RedHat | jss-0:4.4.4-6.el7_6 | * |
Libjss-java | Ubuntu | trusty | * |