Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78323

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

Отчет

This flaw exists in the JSSTrustManager class but is mitigated in default product configurations by the native revocation verification check. Exploitation requires non-default configuration changes (disabling certificate revocation verification) that are not documented or recommended. The server-side TLS validation path (TomcatJSS) uses a different trust manager (JSSNativeTrustManager) that properly delegates to NSS native verification and is not affected.

Меры по смягчению последствий

In default configurations, this flaw is mitigated by the native revocation verification check (certChainRevokeVerify) which is enabled by default on PKI client connections. Ensure that certificate revocation verification remains enabled (do not set isCertRevocationVerify to false). On the server side, the default TomcatJSS configuration uses JSSNativeTrustManager which is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/jssFix deferred
Red Hat Certificate System 11jssFix deferred
Red Hat Enterprise Linux 10jssFix deferred
Red Hat Enterprise Linux 6jssOut of support scope
Red Hat Enterprise Linux 7jssNot affected
Red Hat Enterprise Linux 8pki-core:10.6/jssNot affected
Red Hat Enterprise Linux 9jssFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2521775jss: jss: JSSTrustManager does not verify NSS trust flags on CA certificates

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

CVSS3: 6.5
nvd
24 дня назад

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

CVSS3: 6.5
debian
24 дня назад

A flaw was found in JSS (Java Security Services). The JSSTrustManager ...

CVSS3: 6.5
github
24 дня назад

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

6.5 Medium

CVSS3