Vulnerability Description
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gerrit | < 2.15.22 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/gerrit/issues/detail?id=13858Issue TrackingThird Party Advisory
- https://bugs.chromium.org/p/gerrit/issues/detail?id=13858Issue TrackingThird Party Advisory
FAQ
What is CVE-2021-22553?
CVE-2021-22553 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead t...
How severe is CVE-2021-22553?
CVE-2021-22553 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22553?
Check the references section above for vendor advisories and patch information. Affected products include: Google Gerrit.