<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Gerrit</title>
  <link>https://cvedaily.com/pages/tags/gerrit.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gerrit.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Gerrit</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-2725 – Incorrect authorization in the "submitted together" feature in Gerrit versions 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2725</guid>
    <pubDate>Wed, 13 May 2026 06:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2725</strong></p>
  <p>Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1568 – Access Control Vulnerability in Gerrit chromiumos project configuration in Googl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1568</guid>
    <pubDate>Wed, 16 Apr 2025 23:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1568</strong></p>
  <p>Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24423 – A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24423</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24423</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds triggered by Gerrit.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-46688 – A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46688</guid>
    <pubDate>Mon, 12 Dec 2022 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-46688</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29039 – Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29039</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29039</strong></p>
  <p>Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and description of Base64 Encoded String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22553 – Any git operation is passed through Jetty and a session is created. No expiry is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22553</guid>
    <pubDate>Wed, 17 Feb 2021 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22553</strong></p>
  <p>Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-8920 – An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8920</guid>
    <pubDate>Thu, 10 Dec 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-8920</strong></p>
  <p>An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-8919 – An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8919</guid>
    <pubDate>Thu, 10 Dec 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-8919</strong></p>
  <p>An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16552 – A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16552</guid>
    <pubDate>Tue, 17 Dec 2019 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16552</strong></p>
  <p>A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials, or determine the existence of a file with a given path on the Jenkins master.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16551 – A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16551</guid>
    <pubDate>Tue, 17 Dec 2019 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16551</strong></p>
  <p>A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10467 – Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10467</guid>
    <pubDate>Wed, 23 Oct 2019 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10467</strong></p>
  <p>Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1000106 – An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000106</guid>
    <pubDate>Tue, 13 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1000106</strong></p>
  <p>An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenkins.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1000105 – An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000105</guid>
    <pubDate>Tue, 13 Mar 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1000105</strong></p>
  <p>An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-5737 – The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5737</guid>
    <pubDate>Thu, 12 Jan 2017 23:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-5737</strong></p>
  <p>The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3832 – SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3832</guid>
    <pubDate>Tue, 25 Jul 2006 13:22:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3832</strong></p>
  <p>SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3832">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
