<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2024-0081</id>
    <title>An update for jss is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2024-03-26 06:00:41"/>
    <updated date="2024-03-26 06:00:41"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2021-4213" id="CVE-2021-4213" title="CVE-2021-4213 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service. (CVE-2021-4213)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="jss">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="jss" version="4.9.3" release="1.hce2">
          <filename>jss-4.9.3-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="jss-help" version="4.9.3" release="1.hce2">
          <filename>jss-help-4.9.3-1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="jss" version="4.9.3" release="1.hce2">
          <filename>jss-4.9.3-1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="jss-help" version="4.9.3" release="1.hce2">
          <filename>jss-help-4.9.3-1.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
