[Pkg-freeipa-devel] Bug#1145877: jss: CVE-2026-78323
Salvatore Bonaccorso
carnil at debian.org
Thu Aug 27 13:56:41 BST 2026
Source: jss
Version: 5.9.0~beta3-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for jss.
CVE-2026-78323[0]:
| A flaw was found in JSS (Java Security Services). The
| JSSTrustManager class does not verify NSS trust flags when
| validating CA certificates, allowing certificates present in the NSS
| database without TRUSTED_CA flags to be accepted as trust anchors
| for TLS connections. In non-default configurations where certificate
| revocation checking is disabled, this could allow a man-in-the-
| middle attacker to forge certificates accepted by PKI client
| connections.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-78323
https://www.cve.org/CVERecord?id=CVE-2026-78323
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2521775
Please adjust the affected versions in the BTS as needed.
Actually at time of writing the only reference is the Red Hat bug, so
I'm uncertain about further references, can you explore/check with
upstream?
Regards,
Salvatore
More information about the Pkg-freeipa-devel
mailing list