« Volver al listado

CVE-2020-8920

Estado: ModificadaBaja (3.5)—

An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-8920",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.7,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Gerrit",
          "product": "Gerrit",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "2.15.21",
                  "status": "unaffected"
                },
                {
                  "at": "2.16.25",
                  "status": "unaffected"
                },
                {
                  "at": "3.0.15",
                  "status": "unaffected"
                },
                {
                  "at": "3.1.10",
                  "status": "unaffected"
                },
                {
                  "at": "3.2.5",
                  "status": "unaffected"
                }
              ],
              "version": "stable",
              "lessThan": "2.14.22",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-10T11:15:11.933",
  "references": [
    {
      "url": "https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/2.14.html#21422",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/2.15.html#21521",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/2.16.html#21625",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/3.0.html#3014",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/3.1.html#3110",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://www.gerritcodereview.com/3.2.html#325",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://gerrit.googlesource.com/gerrit/+/45071d6977932bca5a1427c8abad24710fed2e33",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/2.14.html#21422",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/2.15.html#21521",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/2.16.html#21625",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/3.0.html#3014",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/3.1.html#3110",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.gerritcodereview.com/3.2.html#325",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts."
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de filtración de información en Gerrit versiones anteriores a 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5, donde una sobre optimización con el contenedor FilteredRepository omite una comprobación de acceso en los repositorios de todos los usuarios, lo que permite a un atacante conseguir acceso de lectura a la información personal de todos los usuarios asociada con sus cuentas."
    }
  ],
  "lastModified": "2026-06-17T03:27:11.023",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B691AC9-5D19-46ED-B857-EC22AA8DCD0F",
              "versionEndExcluding": "2.14.22",
              "versionStartIncluding": "2.14.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85C99CB5-458B-4A7F-AA2D-B247886C7995",
              "versionEndExcluding": "2.15.21",
              "versionStartIncluding": "2.15.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C858DDA-9464-4FEA-A42F-F7D5B83AA2CE",
              "versionEndExcluding": "2.16.25",
              "versionStartIncluding": "2.16.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B16ADF17-9AC1-40F6-AB4B-0C0C2BDC5632",
              "versionEndExcluding": "3.0.15",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9463501-D097-4BBE-BBC5-78BE8694B4C1",
              "versionEndExcluding": "3.1.10",
              "versionStartIncluding": "3.1.0"
            },
            {
              "criteria": "cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109C49F0-F690-4990-9E07-F3BBB483DDCA",
              "versionEndExcluding": "3.2.5",
              "versionStartIncluding": "3.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}