2.7
CVSSv2

CVE-2020-8920

Published: 10/12/2020 Updated: 07/10/2021
CVSS v2 Base Score: 2.7 | Impact Score: 2.9 | Exploitability Score: 5.1
CVSS v3 Base Score: 3.5 | Impact Score: 1.4 | Exploitability Score: 2.1
VMScore: 240
Vector: AV:A/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An information leak vulnerability exists in Gerrit versions before 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an malicious user to get read access to all users' personal information associated with their accounts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google gerrit