Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.
End of life: 12/2/2024, Latest version: 3.8.10
End of life: 12/2/2024, Latest version: 3.8.10
End of life: 5/19/2025, Latest version: 3.9.11
End of life: 5/19/2025, Latest version: 3.9.11
End of life: 5/17/2024, Latest version: 3.7.9
End of life: 5/17/2024, Latest version: 3.7.9
End of life: 11/25/2023, Latest version: 3.6.8
End of life: 11/25/2023, Latest version: 3.6.8
End of life: 5/19/2023, Latest version: 3.5.6
End of life: 5/19/2023, Latest version: 3.5.6
End of life: 11/9/2022, Latest version: 3.4.8
End of life: 11/9/2022, Latest version: 3.4.8
Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to any of the versions listed above.
End of life: 5/24/2022, Latest version: 3.3.11
End of life: 5/24/2022, Latest version: 3.3.11
End of life: 12/7/2021, Latest version: 3.2.14
End of life: 12/7/2021, Latest version: 3.2.14
End of life: 5/19/2021, Latest version: 3.1.16
End of life: 5/19/2021, Latest version: 3.1.16
End of life: 12/1/2020, Latest version: 3.0.16
End of life: 12/1/2020, Latest version: 3.0.16
End of life: 6/1/2020, Latest version: 2.16.28
End of life: 6/1/2020, Latest version: 2.16.28
End of life: 11/15/2019, Latest version: 2.15.22
End of life: 11/15/2019, Latest version: 2.15.22
End of life: 5/31/2019, Latest version: 2.14.22
End of life: 5/31/2019, Latest version: 2.14.22
Latest version: 2.13.14
Latest version: 2.13.14