<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Gerrit (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/gerrit.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gerrit-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Gerrit (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-1568 – Access Control Vulnerability in Gerrit chromiumos project configuration in Googl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1568</guid>
    <pubDate>Wed, 16 Apr 2025 23:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1568</strong></p>
  <p>Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16551 – A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16551</guid>
    <pubDate>Tue, 17 Dec 2019 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16551</strong></p>
  <p>A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3832 – SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3832</guid>
    <pubDate>Tue, 25 Jul 2006 13:22:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3832</strong></p>
  <p>SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3832">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
