An update for jss is now available for openEuler-20.03-LTS-SP4 Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2024-1221 Final 1.0 1.0 2024-03-01 Initial 2024-03-01 2024-03-01 openEuler SA Tool V1.0 2024-03-01 jss security update An update for jss is now available for openEuler-20.03-LTS-SP4. JSS offers a implementation for java-based applications to use native NSS. Security Fix(es): A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.(CVE-2021-4213) An update for jss is now available for openEuler-20.03-LTS-SP4. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. High jss https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1221 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-4213 https://nvd.nist.gov/vuln/detail/CVE-2021-4213 openEuler-20.03-LTS-SP4 jss-help-4.9.3-1.oe2003sp4.aarch64.rpm jss-4.9.3-1.oe2003sp4.aarch64.rpm jss-debugsource-4.9.3-1.oe2003sp4.aarch64.rpm jss-debuginfo-4.9.3-1.oe2003sp4.aarch64.rpm jss-4.9.3-1.oe2003sp4.src.rpm jss-help-4.9.3-1.oe2003sp4.x86_64.rpm jss-4.9.3-1.oe2003sp4.x86_64.rpm jss-debuginfo-4.9.3-1.oe2003sp4.x86_64.rpm jss-debugsource-4.9.3-1.oe2003sp4.x86_64.rpm A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service. 2024-03-01 CVE-2021-4213 openEuler-20.03-LTS-SP4 High 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H jss security update 2024-03-01 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1221