云虫漏洞库

CVE-2026-78323 - A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections. - 漏洞详情

漏洞编号:CVE-2026-78323

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-78323

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-295

发布/更新时间:2026-08-24 / 2026-08-28

漏洞描述

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

相关链接

相关漏洞

« 返回首页