LOW
Overoptimization leads to private information leak in Gerrit
Published Dec 10, 2020
3.5
LOWCVSS 3.1
EPSS 0.37%
Description
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
Affected products
-
- Version stableStatusaffectedConstraints<2.14.22
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (12)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3896 Advisory
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://github.com/advisories/GHSA-g5q2-cxgq-h2rw Advisory
- https://issues.gerritcodereview.com/issues/40012986
- https://nvd.nist.gov/vuln/detail/CVE-2020-8920
- https://www.gerritcodereview.com/2.14.html#21422 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3015
- https://www.gerritcodereview.com/3.1.html#3110 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3896 | Advisory | |
| https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://github.com/advisories/GHSA-g5q2-cxgq-h2rw | Advisory | |
| https://issues.gerritcodereview.com/issues/40012986 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-8920 | ||
| https://www.gerritcodereview.com/2.14.html#21422 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/2.15.html#21521 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/2.16.html#21625 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.0.html#3014 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.0.html#3015 | ||
| https://www.gerritcodereview.com/3.1.html#3110 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.gerritcodereview.com/3.2.html#325 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
Link CVE-2020-8920
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-3896 GHSA-G5Q2-CXGQ-H2RW Assigner Google
Published Dec 10, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-3896