VYPR
Unrated severityNVD Advisory· Published Feb 17, 2021· Updated Sep 16, 2024

Heap Memory exhaustion in Gerrit

CVE-2021-22553

Description

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.