CVE-2020-8920
Last modified
CVE-2020-8920 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gerrit | >= 2.14.0, < 2.14.22 | |
| Gerrit | >= 2.15.0, < 2.15.21 | |
| Gerrit | >= 2.16.0, < 2.16.25 | |
| Gerrit | >= 3.0.0, < 3.0.15 | |
| Gerrit | >= 3.1.0, < 3.1.10 | |
| Gerrit | >= 3.2.0, < 3.2.5 |
References
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33Issue Tracking, Patch, Vendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release Notes, Vendor Advisory
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33Issue Tracking, Patch, Vendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release Notes, Vendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8920?
How severe is CVE-2020-8920?
How do I fix CVE-2020-8920?
Are you affected by CVE-2020-8920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
