← Back

CVE-2021-22553

nvd nist
Published: Feb 17, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.

Affected (6)

Products: Google: Gerrit
1 product
Gerrit
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Google
Before 2.15.22
From 2.16.0 to 2.16.26
From 3.0.0 to 3.0.16
From 3.1.0 to 3.1.12
From 3.2.0 to 3.2.7
From 3.3.0 to 3.3.2

References (2)

Source: cve-coordination@google.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.