CVE-2020-8920
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an…
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- google/gerrit
- Source
- cve-coordination@google.com
References
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33Issue Tracking, Patch, Vendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release Notes, Vendor Advisory
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33Issue Tracking, Patch, Vendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.