Vulnerability Description
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gerrit | >= 2.15.0, < 2.15.21 |
Related Weaknesses (CWE)
References
- https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca6Issue TrackingPatchVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release NotesVendor Advisory
- https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca6Issue TrackingPatchVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release NotesVendor Advisory
FAQ
What is CVE-2020-8919?
CVE-2020-8919 is a vulnerability with a CVSS score of 3.5 (LOW). An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the defaul...
How severe is CVE-2020-8919?
CVE-2020-8919 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8919?
Check the references section above for vendor advisories and patch information. Affected products include: Google Gerrit.