CVE-2020-8919
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2020
Last modified:
16/12/2020
Description
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.
Impact
Base Score 3.x
3.50
Severity 3.x
LOW
Base Score 2.0
2.70
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | 2.15.0 (including) | 2.15.21 (excluding) |
| cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | 2.16.0 (including) | 2.16.25 (excluding) |
| cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.0.15 (excluding) |
| cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | 3.1.0 (including) | 3.1.10 (excluding) |
| cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | 3.2.0 (including) | 3.2.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65
- https://www.gerritcodereview.com/2.15.html#21521
- https://www.gerritcodereview.com/2.16.html#21625
- https://www.gerritcodereview.com/3.0.html#3014
- https://www.gerritcodereview.com/3.1.html#3110
- https://www.gerritcodereview.com/3.2.html#325



