VYPR
Low severityNVD Advisory· Published Dec 10, 2020· Updated Aug 4, 2024

Overoptimization leads to private information leak in Gerrit

CVE-2020-8920

Description

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.google.gerrit:gerrit-plugin-apiMaven
< 2.14.222.14.22
com.google.gerrit:gerrit-plugin-apiMaven
>= 2.15.0, < 2.15.212.15.21
com.google.gerrit:gerrit-plugin-apiMaven
>= 2.16.0, < 2.16.252.16.25
com.google.gerrit:gerrit-plugin-apiMaven
>= 3.0.0, < 3.0.153.0.15
com.google.gerrit:gerrit-plugin-apiMaven
>= 3.1.0, < 3.1.103.1.10
com.google.gerrit:gerrit-plugin-apiMaven
>= 3.2.0, < 3.2.53.2.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.