Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45q2-f3rm-5r6v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

EPSS

Процентиль: 52%
0.00287
Низкий

7.4 High

CVSS3

Дефекты

CWE-295
CWE-358

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 6 лет назад

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

CVSS3: 6.8
redhat
больше 6 лет назад

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

CVSS3: 7.4
nvd
больше 6 лет назад

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.

CVSS3: 7.4
debian
больше 6 лет назад

A flaw was found in the "Leaf and Chain" OCSP policy implementation in ...

oracle-oval
больше 6 лет назад

ELSA-2019-3067: jss security update (IMPORTANT)

EPSS

Процентиль: 52%
0.00287
Низкий

7.4 High

CVSS3

Дефекты

CWE-295
CWE-358