CVE-2020-8919: Google Gerrit
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.
Affected products
- Google Gerrit: from 2.15.0, before 2.15.21 (fixed in 2.15.21); from 2.16.0, before 2.16.25 (fixed in 2.16.25); from 3.0.0, before 3.0.15 (fixed in 3.0.15); from 3.1.0, before 3.1.10 (fixed in 3.1.10); from 3.2.0, before 3.2.5 (fixed in 3.2.5)
Published 2020-12-10. Last modified 2026-06-17.