Debian Package Tracker
Register | Log in
Subscribe

jss

Network Security Services for Java

Choose email to subscribe with

general
  • source: jss (main)
  • version: 5.9.0~beta3-4
  • maintainer: Debian FreeIPA Team (archive) (DMD)
  • uploaders: Timo Aaltonen [DMD]
  • arch: any
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.8.0-2
  • oldstable: 5.3.0-1
  • testing: 5.9.0~beta3-4
  • unstable: 5.9.0~beta3-4
versioned links
  • 4.8.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.9.0~beta3-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libjss-java
action needed
A new upstream version is available: 5.10.1 high
A new upstream version 5.10.1 is available, you should consider packaging it.
Created: 2025-11-27 Last update: 2026-09-13 07:02
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
Created: 2026-08-25 Last update: 2026-09-10 19:31
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
Created: 2026-08-25 Last update: 2026-09-10 19:31
3 security issues in bullseye high

There are 3 open security issues in bullseye.

1 important issue:
  • CVE-2026-78323: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
2 issues postponed or untriaged:
  • CVE-2021-4213: (needs triaging) A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
  • CVE-2022-4132: (needs triaging) A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).
Created: 2026-08-25 Last update: 2026-08-27 18:01
lintian reports 1 error and 1 warning high
Lintian reports 1 error and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-02-17 Last update: 2026-02-17 22:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.1).
Created: 2020-11-17 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-03-15] jss 5.9.0~beta3-4 MIGRATED to testing (Debian testing watch)
  • [2026-03-10] Accepted jss 5.9.0~beta3-4 (source) into unstable (Timo Aaltonen)
  • [2026-02-17] Accepted jss 5.9.0~beta3-3 (source) into unstable (Timo Aaltonen)
  • [2026-02-16] Accepted jss 5.9.0~beta3-2 (source) into unstable (Timo Aaltonen)
  • [2026-02-16] Accepted jss 5.9.0~beta3-1 (source) into unstable (Timo Aaltonen)
  • [2025-02-07] jss REMOVED from testing (Debian testing watch)
  • [2024-03-06] jss 5.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-29] Accepted jss 5.5.0-1 (source) into unstable (Timo Aaltonen)
  • [2023-08-15] jss 5.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-10] Accepted jss 5.4.2-1 (source) into unstable (Timo Aaltonen)
  • [2023-05-16] Accepted jss 5.4.0-1 (source) into experimental (Timo Aaltonen)
  • [2023-02-20] jss 5.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-10] Accepted jss 5.3.0-1 (source) into unstable (Timo Aaltonen)
  • [2022-11-22] jss 5.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-09] Accepted jss 5.2.0-1 (source) into unstable (Timo Aaltonen)
  • [2022-09-13] jss REMOVED from testing (Debian testing watch)
  • [2022-03-21] jss 5.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-15] Accepted jss 5.1.0-1 (source) into unstable (Timo Aaltonen)
  • [2021-10-25] jss 5.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-18] Accepted jss 5.0.0-1 (source) into unstable (Timo Aaltonen)
  • [2021-09-11] jss 4.9.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-06] Accepted jss 4.9.1-1 (source) into unstable (Timo Aaltonen)
  • [2020-12-08] jss 4.8.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-12-03] Accepted jss 4.8.0-2 (source) into unstable (Timo Aaltonen)
  • [2020-11-07] jss 4.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-10-31] Accepted jss 4.8.0-1 (source) into unstable (Timo Aaltonen)
  • [2020-09-19] jss 4.7.3-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-14] Accepted jss 4.7.3-1 (source) into unstable (Timo Aaltonen)
  • [2020-08-18] jss 4.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-08-13] Accepted jss 4.7.2-1 (source) into unstable (Timo Aaltonen)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 2
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (1, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.9.0~beta3-3ubuntu1
  • patches for 5.9.0~beta3-3ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing