Beveiligingsadvies

CVE-2026-78323

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-24 11:11:01
Laatst bijgewerkt 2026-08-24 11:50:28
Toegewezen door redhat
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.