VYPR
Unrated severityNVD Advisory· Published Apr 16, 2025· Updated May 20, 2025

CVE-2025-1568

CVE-2025-1568

Description

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

Affected products

2
  • Google/Chromellm-fuzzy2 versions
    =16063.87.0+ 1 more
    • (no CPE)range: =16063.87.0
    • (no CPE)range: 16063.87.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.