PT-2021-15140 · Jetty+1 · Jetty+1

Antoine Musso

·

Published

2021-02-17

·

Updated

2022-10-25

·

CVE-2021-22553

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gerrit (affected versions not specified)
Description The issue arises when any git operation is passed through Jetty, creating a session without an expiry date. Since Jetty does not automatically dispose of the session, multiple git actions can lead to heap memory exhaustion for Gerrit servers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-22553

Affected Products

Gerrit
Jetty