{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"jss security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for jss is now available for openEuler-22.03-LTS.",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"JSS offers a implementation for java-based applications to use native NSS.\n\nSecurity Fix(es):\n\nA flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.(CVE-2021-4213)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for jss is now available for openEuler-22.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"jss",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2024-1208",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1208"
			},
			{
				"summary":"CVE-2021-4213",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail?cveId=CVE-2021-4213&packageName=jss"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4213"
			},
			{
				"summary":"openEuler-SA-2024-1208 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openeuler-sa-2024-1208.json"
			}
		],
		"title":"An update for jss is now available for openEuler-22.03-LTS",
		"tracking":{
			"initial_release_date":"2024-02-23T09:11:59+08:00",
			"revision_history":[
				{
					"date":"2024-02-23T09:11:59+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				},
				{
					"date":"2024-10-31T09:11:59+08:00",
					"summary":"final",
					"number":"2.0.0"
				}
			],
			"generator":{
				"date":"2024-10-31T09:11:59+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2024-10-31T09:11:59+08:00",
			"id":"openEuler-SA-2024-1208",
			"version":"2.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"openEuler-22.03-LTS",
									"name":"openEuler-22.03-LTS"
								},
								"name":"openEuler-22.03-LTS",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-debuginfo-4.9.3-1.oe2203.aarch64.rpm",
									"name":"jss-debuginfo-4.9.3-1.oe2203.aarch64.rpm"
								},
								"name":"jss-debuginfo-4.9.3-1.oe2203.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-help-4.9.3-1.oe2203.aarch64.rpm",
									"name":"jss-help-4.9.3-1.oe2203.aarch64.rpm"
								},
								"name":"jss-help-4.9.3-1.oe2203.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-4.9.3-1.oe2203.aarch64.rpm",
									"name":"jss-4.9.3-1.oe2203.aarch64.rpm"
								},
								"name":"jss-4.9.3-1.oe2203.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-debugsource-4.9.3-1.oe2203.aarch64.rpm",
									"name":"jss-debugsource-4.9.3-1.oe2203.aarch64.rpm"
								},
								"name":"jss-debugsource-4.9.3-1.oe2203.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-4.9.3-1.oe2203.src.rpm",
									"name":"jss-4.9.3-1.oe2203.src.rpm"
								},
								"name":"jss-4.9.3-1.oe2203.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-help-4.9.3-1.oe2203.x86_64.rpm",
									"name":"jss-help-4.9.3-1.oe2203.x86_64.rpm"
								},
								"name":"jss-help-4.9.3-1.oe2203.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-debugsource-4.9.3-1.oe2203.x86_64.rpm",
									"name":"jss-debugsource-4.9.3-1.oe2203.x86_64.rpm"
								},
								"name":"jss-debugsource-4.9.3-1.oe2203.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-4.9.3-1.oe2203.x86_64.rpm",
									"name":"jss-4.9.3-1.oe2203.x86_64.rpm"
								},
								"name":"jss-4.9.3-1.oe2203.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"jss-debuginfo-4.9.3-1.oe2203.x86_64.rpm",
									"name":"jss-debuginfo-4.9.3-1.oe2203.x86_64.rpm"
								},
								"name":"jss-debuginfo-4.9.3-1.oe2203.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-debuginfo-4.9.3-1.oe2203.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.aarch64",
					"name":"jss-debuginfo-4.9.3-1.oe2203.aarch64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-help-4.9.3-1.oe2203.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.aarch64",
					"name":"jss-help-4.9.3-1.oe2203.aarch64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-4.9.3-1.oe2203.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.aarch64",
					"name":"jss-4.9.3-1.oe2203.aarch64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-debugsource-4.9.3-1.oe2203.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.aarch64",
					"name":"jss-debugsource-4.9.3-1.oe2203.aarch64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-4.9.3-1.oe2203.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.src",
					"name":"jss-4.9.3-1.oe2203.src as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-help-4.9.3-1.oe2203.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.x86_64",
					"name":"jss-help-4.9.3-1.oe2203.x86_64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-debugsource-4.9.3-1.oe2203.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.x86_64",
					"name":"jss-debugsource-4.9.3-1.oe2203.x86_64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-4.9.3-1.oe2203.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.x86_64",
					"name":"jss-4.9.3-1.oe2203.x86_64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"jss-debuginfo-4.9.3-1.oe2203.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.x86_64",
					"name":"jss-debuginfo-4.9.3-1.oe2203.x86_64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2021-4213",
			"notes":[
				{
					"text":"A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.aarch64",
					"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.aarch64",
					"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.aarch64",
					"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.aarch64",
					"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.src",
					"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.x86_64",
					"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.x86_64",
					"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.x86_64",
					"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.src",
						"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.x86_64"
					],
					"details":"jss security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1208"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.aarch64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.src",
						"openEuler-22.03-LTS:jss-help-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-debugsource-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-4.9.3-1.oe2203.x86_64",
						"openEuler-22.03-LTS:jss-debuginfo-4.9.3-1.oe2203.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2021-4213"
		}
	]
}