VYPR
Medium severity6.5NVD Advisory· Published Feb 17, 2021· Updated Jun 17, 2026

CVE-2021-22553

CVE-2021-22553

Description

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.

Affected products

4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.