VDB
CVE-2020-8920
CVE-2020-8920
PUBLISHED
CVSS 3.5 LOW
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
EPSS 0.37% · 31.1th percentile
Risk Scores
CVSS 3.1
3.5
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.37%
31.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gerrit | 2.14.0, 2.15.0, 2.16.0 | |
| Maven | com.google.gerrit:gerrit-plugin-api | 2.16.0, 3.0.0, 3.2.0 |
| Gerrit | Gerrit | * |
Timeline
- Dec 10, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://www.gerritcodereview.com/3.2.html#325 url
- https://www.gerritcodereview.com/2.15.html#21521 url
- https://www.gerritcodereview.com/2.16.html#21625 url
- https://www.gerritcodereview.com/3.0.html#3014 url
- https://www.gerritcodereview.com/3.1.html#3110 url
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33 url
- https://www.gerritcodereview.com/2.14.html#21422 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-8920 advisory
- https://issues.gerritcodereview.com/issues/40012986 url
- https://www.gerritcodereview.com/3.0.html#3015 url