Source: jss Version: 4.6.1-3 Severity: grave Tags: security upstream Forwarded: https://github.com/dogtagpki/jss/pull/284
Hi, The following vulnerability was published for jss. CVE-2019-14823[0]: | A flaw was found in the "Leaf and Chain" OCSP policy implementation in | JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it | implicitly trusted the root certificate of a certificate chain. | Applications using this policy may not properly verify the chain and | could be vulnerable to attacks such as Man in the Middle. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-14823 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14823 [1] https://github.com/dogtagpki/jss/pull/284 [2] https://github.com/dogtagpki/jss/commit/be37ff4738b4696d529a13b6ed33c7ac56d97ba4 Please adjust the affected versions in the BTS as needed. Regards, Salvatore