An update for jss is now available for openEuler-20.03-LTS-SP1
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2024-1220
Final
1.0
1.0
2024-03-01
Initial
2024-03-01
2024-03-01
openEuler SA Tool V1.0
2024-03-01
jss security update
An update for jss is now available for openEuler-20.03-LTS-SP1.
JSS offers a implementation for java-based applications to use native NSS.
Security Fix(es):
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.(CVE-2021-4213)
An update for jss is now available for openEuler-20.03-LTS-SP1.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
jss
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1220
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-4213
https://nvd.nist.gov/vuln/detail/CVE-2021-4213
openEuler-20.03-LTS-SP1
jss-help-4.9.3-1.oe1.aarch64.rpm
jss-debugsource-4.9.3-1.oe1.aarch64.rpm
jss-4.9.3-1.oe1.aarch64.rpm
jss-debuginfo-4.9.3-1.oe1.aarch64.rpm
jss-4.9.3-1.oe1.src.rpm
jss-debuginfo-4.9.3-1.oe1.x86_64.rpm
jss-help-4.9.3-1.oe1.x86_64.rpm
jss-debugsource-4.9.3-1.oe1.x86_64.rpm
jss-4.9.3-1.oe1.x86_64.rpm
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
2024-03-01
CVE-2021-4213
openEuler-20.03-LTS-SP1
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
jss security update
2024-03-01
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1220