Description
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3896 | An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts. |
Github GHSA |
GHSA-g5q2-cxgq-h2rw | Information leak in Gerrit |
References
History
No history.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-04T10:12:10.990Z
Reserved: 2020-02-12T00:00:00.000Z
Link: CVE-2020-8920
No data.
Status : Modified
Published: 2020-12-10T11:15:11.933
Modified: 2024-11-21T05:39:41.157
Link: CVE-2020-8920
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA