VulnerabilityModified
CVE-2021-4213
This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
HIGH 7.5EPSS 1.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- dogtagpki/network security services for java · redhat/enterprise linux · debian/debian linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2021-4213Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2042900Issue Tracking, Patch, Third Party Advisory
- https://github.com/dogtagpki/jss/commit/3aabe0e9d59b0a42e68ac8cd0468f9c5179967d2Patch, Third Party Advisory
- https://github.com/dogtagpki/jss/commit/5922560a78d0dee61af8a33cc9cfbf4cfa291448Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2021-4213Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-4213Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2042900Issue Tracking, Patch, Third Party Advisory
- https://github.com/dogtagpki/jss/commit/3aabe0e9d59b0a42e68ac8cd0468f9c5179967d2Patch, Third Party Advisory
- https://github.com/dogtagpki/jss/commit/5922560a78d0dee61af8a33cc9cfbf4cfa291448Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2021-4213Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.