CVE-2021-4213
7.5
HIGH
CVSS 3.1
EPSS 1.2%
Description
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
How to fix CVE-2021-4213
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/jss—no fix listed
Is CVE-2021-4213 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |