Java Security Services (JSS) is a java native interface which provides a bridge for java-based applications to use native Network Security Services (NSS). This only works with gcj. Other JREs require that JCE providers be signed.
Security Fix(es):
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.(CVE-2026-78323)
{
"severity": "Medium"
}{
"aarch64": [
"jss-5.4.2-3.oe2403sp1.aarch64.rpm",
"jss-debuginfo-5.4.2-3.oe2403sp1.aarch64.rpm",
"jss-debugsource-5.4.2-3.oe2403sp1.aarch64.rpm",
"jss-help-5.4.2-3.oe2403sp1.aarch64.rpm"
],
"src": [
"jss-5.4.2-3.oe2403sp1.src.rpm"
],
"x86_64": [
"jss-5.4.2-3.oe2403sp1.x86_64.rpm",
"jss-debuginfo-5.4.2-3.oe2403sp1.x86_64.rpm",
"jss-debugsource-5.4.2-3.oe2403sp1.x86_64.rpm",
"jss-help-5.4.2-3.oe2403sp1.x86_64.rpm"
]
}