Back

LOW

Overoptimization leads to private information leak in Gerrit

Published Dec 10, 2020

Description

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2022-3896 GHSA-G5Q2-CXGQ-H2RW