Bugzilla – Bug 1205721
VUL-0: CVE-2022-4132: tomcat,tomcat6: Memory leak
Last modified: 2024-07-19 14:43:46 UTC
rh#2147372 An external upstream contributor has discovered a memory leak in JSS. It requires non-standard configuration, but is a low-effort DoS vector if configured that way (repeatedly hit the login page). further information below in a forwarded email. References: https://bugzilla.redhat.com/show_bug.cgi?id=2147372 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-4132
I'm wondering if we can close this bug and re-open it when information will be disclosed. Thanks
Please leave the bug open. We will check if there is some development in the future.
according to https://bugzilla.redhat.com/show_bug.cgi?id=2147372 this is not a tomcat issue but tomcatjss. Since we don't release this package, I think we can close it
Closing bug.