{"schema_version":"1.7.2","id":"OESA-2026-4135","modified":"2026-09-30T13:46:56Z","published":"2026-09-30T13:46:56Z","upstream":["CVE-2026-78323"],"summary":"jss security update","details":"Java Security Services (JSS) is a java native interface which provides a bridge for java-based applications to use native Network Security Services (NSS). This only works with gcj. Other JREs require that JCE providers be signed.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.(CVE-2026-78323)","affected":[{"package":{"ecosystem":"openEuler:22.03-LTS-SP4","name":"jss","purl":"pkg:rpm/openEuler/jss&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.0-4.oe2203sp4"}]}],"ecosystem_specific":{"aarch64":["jss-5.1.0-4.oe2203sp4.aarch64.rpm","jss-debuginfo-5.1.0-4.oe2203sp4.aarch64.rpm","jss-debugsource-5.1.0-4.oe2203sp4.aarch64.rpm","jss-help-5.1.0-4.oe2203sp4.aarch64.rpm"],"src":["jss-5.1.0-4.oe2203sp4.src.rpm"],"x86_64":["jss-5.1.0-4.oe2203sp4.x86_64.rpm","jss-debuginfo-5.1.0-4.oe2203sp4.x86_64.rpm","jss-debugsource-5.1.0-4.oe2203sp4.x86_64.rpm","jss-help-5.1.0-4.oe2203sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4135"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78323"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"database_specific":{"severity":"Medium"}}
