Bug 2147372 (CVE-2022-4132) - CVE-2022-4132 Tomcat: Memory leak
Summary: CVE-2022-4132 Tomcat: Memory leak
Keywords:
Status: NEW
Alias: CVE-2022-4132
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2157648 2152893 2152894 2152896 2157647
Blocks: 2147373
TreeView+ depends on / blocked
 
Reported: 2022-11-23 20:23 UTC by Sage McTaggart
Modified: 2023-07-07 08:30 UTC (History)
16 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sage McTaggart 2022-11-23 20:23:01 UTC
An external upstream contributor has discovered a memory leak in JSS.
It requires non-standard configuration, but is a low-effort DoS vector if
configured that way (repeatedly hit the login page).
further information below in a forwarded email.

Comment 6 Patrick Del Bello 2023-01-02 13:10:15 UTC
Created tomcat tracking bugs for this issue:

Affects: epel-all [bug 2157647]
Affects: fedora-all [bug 2157648]


Note You need to log in before you can comment on or make changes to this bug.