CVE-2021-22553
- EPSS 0.15%
- Published 17.02.2021 12:15:12
- Last modified 21.11.2024 05:50:19
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We ...
CVE-2020-8919
- EPSS 0.08%
- Published 10.12.2020 11:15:11
- Last modified 21.11.2024 05:39:41
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's pers...
CVE-2020-8920
- EPSS 0.08%
- Published 10.12.2020 11:15:11
- Last modified 21.11.2024 05:39:41
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing a...