Gerrit 2.15
Gerrit 2.15
The Gerrit 2.15 reached end of service life on Nov 15, 2019 — Gerrit no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Gerrit 2.15 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- gerrit
- release
- 2.15
- product Label
- Gerrit
- release Label
- 2.15
- codename
- lts
- latest Version
- 2.15.22
- release Date
- 2018-03-28
- maintained
- source Url
- https://endoflife.date/gerrit
Lifecycle Dates
- End of Service Life
- Nov 15, 2019
- Last OEM Support
- Nov 15, 2019
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Gerrit 2.15 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Gerrit 2.15?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Gerrit 2.15 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Gerrit 2.15 Support: Frequently Asked Questions
Is the Gerrit 2.15 still supported?
Gerrit ended support for the Gerrit 2.15 on Nov 15, 2019 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Gerrit 2.15 end of service life (EOSL) date?
Gerrit lists the end of service life for the Gerrit 2.15 as Nov 15, 2019.
Can I keep using the Gerrit 2.15 after its EOSL date?
Yes. EOSL means Gerrit stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Gerrit 2.15 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Gerrit 2.15
4 published CVEs affect the Gerrit 2.15. Gerrit no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2021-22553 | MEDIUM | 6.5 | Feb 17, 2021 | Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above. |
| CVE-2026-2725 | MEDIUM | 6.0 | May 13, 2026 | Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change. |
| CVE-2020-8920 | LOW | 3.5 | Dec 10, 2020 | An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts. |
| CVE-2020-8919 | LOW | 3.5 | Dec 10, 2020 | An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access. |