Description
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.
No analysis available yet.
Remediation
Vendor Solution
We recommend upgrading Gerrit to any version listed above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9694 | Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above. |
References
| Link | Providers |
|---|---|
| https://bugs.chromium.org/p/gerrit/issues/detail?id=13858 |
|
History
No history.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-09-16T19:51:15.662Z
Reserved: 2021-01-05T00:00:00.000Z
Link: CVE-2021-22553
No data.
Status : Modified
Published: 2021-02-17T12:15:12.063
Modified: 2024-11-21T05:50:19.220
Link: CVE-2021-22553
No data.
OpenCVE Enrichment
No data.
EUVD