CVE-2022-4132: Memory leak on tls connections
A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).
Other sources
An external upstream contributor has discovered a memory leak in JSS. It requires non-standard configuration, but is a low-effort DoS vector if configured that way (repeatedly hit the login page). further information below in a forwarded email.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-4132?
CVE-2022-4132 is a vulnerability found in JSS that can result in a low-effort denial-of-service (DoS) attack if configured in a specific way.
What is the severity of CVE-2022-4132?
The severity of CVE-2022-4132 is rated as medium with a CVSS score of 5.9.
How does CVE-2022-4132 affect JSS?
CVE-2022-4132 affects JSS by causing a memory leak, leading to a potential DoS attack if the application is configured in a non-standard way.
Which versions of JSS are affected by CVE-2022-4132?
Versions up to and excluding 5.5.0 of JSS are vulnerable to CVE-2022-4132.
How can CVE-2022-4132 be mitigated?
To mitigate CVE-2022-4132, it is recommended to upgrade JSS to version 5.5.0 or later.