{"id":"MGASA-2020-0018","summary":"Updated jss packages fix security vulnerability","details":"Updated jss packages fix security vulnerability:\n\nA flaw was found in the \"Leaf and Chain\" OCSP policy implementation in\nJSS CryptoManager, where it implicitly trusted the root certificate of\na certificate chain. Applications using this policy may not properly\nverify the chain and could be vulnerable to attacks such as Man in the\nMiddle (CVE-2019-14823).\n","modified":"2026-04-16T04:44:36.615886900Z","published":"2020-01-05T15:37:51Z","upstream":["CVE-2019-14823"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0018.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25958"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O53NXVKMF7PJCPMCJQHLMSYCUGDHGBVE/"}],"affected":[{"package":{"name":"jss","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/jss?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.2-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0018.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}