CVE-2019-14823

CVE-2019-14823

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS’ CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

Source: CVE-2019-14823

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다