← Back

CVE-2020-8920

nvd nist
Published: Dec 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD

Description

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.

Affected (6)

Products: Google: Gerrit
1 product
Gerrit
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Google
From 2.14.0 to 2.14.22
From 2.15.0 to 2.15.21
From 2.16.0 to 2.16.25
From 3.0.0 to 3.0.15
From 3.1.0 to 3.1.10
From 3.2.0 to 3.2.5

References (14)

Source: cve-coordination@google.com
Issue TrackingPatchVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: cve-coordination@google.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.