CVE-2020-8920
Information leak in Gerrit
EPSS 0.08%
描述
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.
如何修補 CVE-2020-8920
要修補 CVE-2020-8920,請將受影響套件升級到下列已修補版本。
- Maven/com.google.gerrit:gerrit-plugin-api—升級至 2.14.22 或更新版本
CVE-2020-8920 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.14.22