CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.4. See the original NVD description below for full technical details.
CVE
CVE-2019-14823
Severity
HIGH
CVSS
7.4
EPSS
0.86%
Original NVD Description
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle.
Related CVEs
Other vulnerabilities affecting the same vendor(s)