CVE-2021-22553HIGHCVSS 7.5≥ unspecified, < 2.15.22·≥ unspecified, < 2.16.26+4 more2021-02-17
CVE-2021-22553 [MEDIUM] CWE-400 CVE-2021-22553: Any git operation is passed through Jetty and a session is created. No expiry is set for the session
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.
cvelistv5nvd