An external upstream contributor has discovered a memory leak in JSS. It requires non-standard configuration, but is a low-effort DoS vector if configured that way (repeatedly hit the login page). further information below in a forwarded email.
Created tomcat tracking bugs for this issue: Affects: epel-all [bug 2157647] Affects: fedora-all [bug 2157648]