Una vulnerabilità perdita di informazioni esiste in versioni Gerrit prima 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 dove un controllo di accesso manca sul ramo API REST permette ad un aggressore con solo l’insieme predefinito di privilegi di leggere i dati di account personali di tutti gli altri utenti così come sotto-alberi con accesso riservato.
https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65
https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65
https://www.gerritcodereview.com/2.15.html#21521
https://www.gerritcodereview.com/2.15.html#21521
https://www.gerritcodereview.com/2.16.html#21625
https://www.gerritcodereview.com/2.16.html#21625
https://www.gerritcodereview.com/3.0.html#3014
https://www.gerritcodereview.com/3.0.html#3014
https://www.gerritcodereview.com/3.1.html#3110
https://www.gerritcodereview.com/3.1.html#3110
https://www.gerritcodereview.com/3.2.html#325
https://www.gerritcodereview.com/3.2.html#325
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8919