Vulnerability Description
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gerrit | >= 2.14.0, < 2.14.22 |
Related Weaknesses (CWE)
References
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e3Issue TrackingPatchVendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release NotesVendor Advisory
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e3Issue TrackingPatchVendor Advisory
- https://www.gerritcodereview.com/2.14.html#21422Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.15.html#21521Release NotesVendor Advisory
- https://www.gerritcodereview.com/2.16.html#21625Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.0.html#3014Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.1.html#3110Release NotesVendor Advisory
- https://www.gerritcodereview.com/3.2.html#325Release NotesVendor Advisory
FAQ
What is CVE-2020-8920?
CVE-2020-8920 is a vulnerability with a CVSS score of 3.5 (LOW). An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verificati...
How severe is CVE-2020-8920?
CVE-2020-8920 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8920?
Check the references section above for vendor advisories and patch information. Affected products include: Google Gerrit.