LOW
Information leakage in Gerrit
Published Dec 10, 2020
3.5
LOWCVSS 3.1
EPSS 0.32%
Description
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.
Affected products
-
- Version stableStatusaffectedConstraints<2.15.21
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29753 Advisory
- https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29753 | Advisory | |
| https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://www.gerritcodereview.com/2.15.html#21521 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/2.16.html#21625 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.0.html#3014 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.1.html#3110 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.2.html#325 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
Link CVE-2020-8919
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-29753 Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-29753