Debian Package Tracker
Register | Log in
Subscribe

jss

Choose email to subscribe with

general
  • source: jss (main)
  • version: 5.10.1-1
  • maintainer: Debian FreeIPA Team (archive) (DMD)
  • uploaders: Timo Aaltonen [DMD]
  • arch: any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.8.0-2
  • oldstable: 5.3.0-1
  • testing: 5.9.0~beta3-4
  • unstable: 5.10.1-1
versioned links
  • 4.8.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.9.0~beta3-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.10.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libjss-java
  • libjss-tools
action needed
Marked for autoremoval on 16 October: #1148197 high
Version 5.9.0~beta3-4 of jss is marked for autoremoval from testing on Fri 16 Oct 2026. It is affected by #1148197. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-25 Last update: 2026-10-04 07:32
lintian reports 3 warnings high
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-02-17 Last update: 2026-09-29 23:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
Created: 2026-08-25 Last update: 2026-09-29 18:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
Created: 2026-08-25 Last update: 2026-09-29 18:00
3 security issues in bullseye high

There are 3 open security issues in bullseye.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
2 issues postponed or untriaged:
  • CVE-2021-4213: (needs triaging) A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
  • CVE-2022-4132: (needs triaging) A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).
Created: 2026-08-25 Last update: 2026-08-27 18:01
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit ab036578eae0dc9d48b12e3ff08df80e4132d833
Author: Timo Aaltonen <tjaalton@debian.org>
Date:   Wed Sep 30 15:13:04 2026 +0300

    rules: Clean up generated files.

commit 2e4af4d2e6f5bc12f2cd49c138598737d8e41c5b
Author: Timo Aaltonen <tjaalton@debian.org>
Date:   Wed Sep 30 15:10:06 2026 +0300

    rules: Fix running tests.

commit 6732f180692393285a5bd607867168afb4575cb8
Author: Timo Aaltonen <tjaalton@debian.org>
Date:   Tue Sep 29 15:06:16 2026 +0300

    watch: Use github template.
Created: 2026-09-30 Last update: 2026-09-30 15:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2020-11-17 Last update: 2026-09-29 18:00
testing migrations
  • excuses:
    • Blocked by: libslf4j-java
    • Migration status for jss (5.9.0~beta3-4 to 5.10.1-1): Waiting for another item to be ready to migrate (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Depends: jss libslf4j-java (not considered)
    • ∙ ∙ Invalidated by dependency
    • Additional info (not blocking):
    • ∙ ∙ Updating jss will fix bugs in testing: #1148197
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/j/jss.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-09-29] Accepted jss 5.10.1-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Timo Aaltonen)
  • [2026-03-15] jss 5.9.0~beta3-4 MIGRATED to testing (Debian testing watch)
  • [2026-03-10] Accepted jss 5.9.0~beta3-4 (source) into unstable (Timo Aaltonen)
  • [2026-02-17] Accepted jss 5.9.0~beta3-3 (source) into unstable (Timo Aaltonen)
  • [2026-02-16] Accepted jss 5.9.0~beta3-2 (source) into unstable (Timo Aaltonen)
  • [2026-02-16] Accepted jss 5.9.0~beta3-1 (source) into unstable (Timo Aaltonen)
  • [2025-02-07] jss REMOVED from testing (Debian testing watch)
  • [2024-03-06] jss 5.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-29] Accepted jss 5.5.0-1 (source) into unstable (Timo Aaltonen)
  • [2023-08-15] jss 5.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-10] Accepted jss 5.4.2-1 (source) into unstable (Timo Aaltonen)
  • [2023-05-16] Accepted jss 5.4.0-1 (source) into experimental (Timo Aaltonen)
  • [2023-02-20] jss 5.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-10] Accepted jss 5.3.0-1 (source) into unstable (Timo Aaltonen)
  • [2022-11-22] jss 5.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-09] Accepted jss 5.2.0-1 (source) into unstable (Timo Aaltonen)
  • [2022-09-13] jss REMOVED from testing (Debian testing watch)
  • [2022-03-21] jss 5.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-15] Accepted jss 5.1.0-1 (source) into unstable (Timo Aaltonen)
  • [2021-10-25] jss 5.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-18] Accepted jss 5.0.0-1 (source) into unstable (Timo Aaltonen)
  • [2021-09-11] jss 4.9.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-06] Accepted jss 4.9.1-1 (source) into unstable (Timo Aaltonen)
  • [2020-12-08] jss 4.8.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-12-03] Accepted jss 4.8.0-2 (source) into unstable (Timo Aaltonen)
  • [2020-11-07] jss 4.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-10-31] Accepted jss 4.8.0-1 (source) into unstable (Timo Aaltonen)
  • [2020-09-19] jss 4.7.3-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-14] Accepted jss 4.7.3-1 (source) into unstable (Timo Aaltonen)
  • [2020-08-18] jss 4.7.2-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 2
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.9.0~beta3-3ubuntu1
  • patches for 5.9.0~beta3-3ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing