JSS是JSS组织的一个 CSS 创作工具。 JSS存在加密问题漏洞,该漏洞源于JSSTrustManager类在验证CA证书时未验证NSS信任标志,在禁用证书吊销检查的非默认配置下,可能导致中间人攻击者伪造PKI客户端连接接受的证书。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | any |
affected |
| Red Hat | Red Hat Certificate System 11 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Certificate System 10 | - |
cpe:/a:redhat:certificate_system:10
|
|
| Red Hat | Red Hat Certificate System 11 | - |
cpe:/a:redhat:certificate_system:11
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71366 | 7.7 HIGH | Awx: notification backends allow ssrf and credential leakage |
| CVE-2026-71364 | 7.2 HIGH | Awx: project archive extraction allows path traversal file writes |
| CVE-2026-19685 | 7.1 HIGH | Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user rest |
| CVE-2026-78367 | 7.0 HIGH | Rpm: rpmbuild gettarspec() crafted tar member name → macro injection |
No comments yet