First published: Sun Jan 31 2021(Updated: )
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Gerrit | <2.15.22 | |
Google Gerrit | >=2.16.0<2.16.26 | |
Google Gerrit | >=3.0.0<3.0.16 | |
Google Gerrit | >=3.1.0<3.1.12 | |
Google Gerrit | >=3.2.0<3.2.7 | |
Google Gerrit | >=3.3.0<3.3.2 |
We recommend upgrading Gerrit to any version listed above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.