CVE-2020-8920
Estado: ModificadaBaja (3.5)—
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-285
- NVD-CWE-Other
Referencias
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33
- https://www.gerritcodereview.com/2.14.html#21422
- https://www.gerritcodereview.com/2.15.html#21521
- https://www.gerritcodereview.com/2.16.html#21625
- https://www.gerritcodereview.com/3.0.html#3014
- https://www.gerritcodereview.com/3.1.html#3110
- https://www.gerritcodereview.com/3.2.html#325
- https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33
- https://www.gerritcodereview.com/2.14.html#21422
- https://www.gerritcodereview.com/2.15.html#21521
- https://www.gerritcodereview.com/2.16.html#21625
- https://www.gerritcodereview.com/3.0.html#3014
- https://www.gerritcodereview.com/3.1.html#3110
- https://www.gerritcodereview.com/3.2.html#325
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-8920",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.7,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.1,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "cve-coordination@google.com",
"affectedData": [
{
"vendor": "Gerrit",
"product": "Gerrit",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "2.15.21",
"status": "unaffected"
},
{
"at": "2.16.25",
"status": "unaffected"
},
{
"at": "3.0.15",
"status": "unaffected"
},
{
"at": "3.1.10",
"status": "unaffected"
},
{
"at": "3.2.5",
"status": "unaffected"
}
],
"version": "stable",
"lessThan": "2.14.22",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-12-10T11:15:11.933",
"references": [
{
"url": "https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/2.14.html#21422",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/2.15.html#21521",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/2.16.html#21625",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/3.0.html#3014",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/3.1.html#3110",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://www.gerritcodereview.com/3.2.html#325",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve-coordination@google.com"
},
{
"url": "https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/2.14.html#21422",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/2.15.html#21521",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/2.16.html#21625",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/3.0.html#3014",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/3.1.html#3110",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.gerritcodereview.com/3.2.html#325",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-coordination@google.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de filtración de información en Gerrit versiones anteriores a 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5, donde una sobre optimización con el contenedor FilteredRepository omite una comprobación de acceso en los repositorios de todos los usuarios, lo que permite a un atacante conseguir acceso de lectura a la información personal de todos los usuarios asociada con sus cuentas."
}
],
"lastModified": "2026-06-17T03:27:11.023",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B691AC9-5D19-46ED-B857-EC22AA8DCD0F",
"versionEndExcluding": "2.14.22",
"versionStartIncluding": "2.14.0"
},
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85C99CB5-458B-4A7F-AA2D-B247886C7995",
"versionEndExcluding": "2.15.21",
"versionStartIncluding": "2.15.0"
},
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C858DDA-9464-4FEA-A42F-F7D5B83AA2CE",
"versionEndExcluding": "2.16.25",
"versionStartIncluding": "2.16.0"
},
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B16ADF17-9AC1-40F6-AB4B-0C0C2BDC5632",
"versionEndExcluding": "3.0.15",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9463501-D097-4BBE-BBC5-78BE8694B4C1",
"versionEndExcluding": "3.1.10",
"versionStartIncluding": "3.1.0"
},
{
"criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "109C49F0-F690-4990-9E07-F3BBB483DDCA",
"versionEndExcluding": "3.2.5",
"versionStartIncluding": "3.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-coordination@google.com"
}