Vulnerabilities > CVE-2021-4213 - Memory Leak vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
dogtagpki
redhat
debian
CWE-401

Summary

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.

Vulnerable Configurations

Part Description Count
Application
Dogtagpki
43
OS
Redhat
1
OS
Debian
2