« Volver al listado

CVE-2021-22553

Estado: ModificadaAlta (7.5)—

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-22553",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google LLC",
          "product": "Gerrit",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.15.22",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.16.26",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.0.16",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.1.12",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.2.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.3.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-17T12:15:12.063",
  "references": [
    {
      "url": "https://bugs.chromium.org/p/gerrit/issues/detail?id=13858",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://bugs.chromium.org/p/gerrit/issues/detail?id=13858",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-772"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above."
    },
    {
      "lang": "es",
      "value": "Cualquier operación git es pasada a través de Jetty y es creada una sesión. No es ajustada ninguna fecha de expiración para la sesión y Jetty no elimina automáticamente la sesión. Durante múltiples acciones git, esto puede conllevar a un agotamiento de la memoria de la pila para los servidores de Gerrit. Recomendamos actualizar Gerrit a cualquiera de las versiones mencionadas anteriormente"
    }
  ],
  "lastModified": "2026-06-17T03:37:25.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA106DC3-BD15-42E3-80D1-C83267AE45D5",
              "versionEndExcluding": "2.15.22"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86ABAE59-1B32-4598-9513-793862CCC88C",
              "versionEndExcluding": "2.16.26",
              "versionStartIncluding": "2.16.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB09EBE5-D228-49EE-80AC-978661C5284A",
              "versionEndExcluding": "3.0.16",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E263BE88-AF2F-4D06-A7CF-A9D806EC3A7E",
              "versionEndExcluding": "3.1.12",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5660350-95CD-4E70-A2A7-92D4E0554776",
              "versionEndExcluding": "3.2.7",
              "versionStartIncluding": "3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D44029D-AC7C-4D24-BEEA-25712B1DF63D",
              "versionEndExcluding": "3.3.2",
              "versionStartIncluding": "3.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}