An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.
Conclusion & alert: CVE-2020-8919 is rated Low Risk (22.3/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.32%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.08% | 0.32% | +0.24% |
| 2 | 2025-03-17 | 0.05% | 0.08% | +0.03% |
| 3 | 2024-12-17 | — | 0.05% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 3.1 | LOW |
|
2.1 | 1.4 | [email protected] |
| 3.5 | 3.1 | LOW |
|
2.1 | 1.4 | [email protected] |
| 2.7 | 2.0 | LOW |
|
5.1 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| gerrit | >= 2.15.0, < 2.15.21 | cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | |
| gerrit | >= 2.16.0, < 2.16.25 | cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | |
| gerrit | >= 3.0.0, < 3.0.15 | cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | |
| gerrit | >= 3.1.0, < 3.1.10 | cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* | |
| gerrit | >= 3.2.0, < 3.2.5 | cpe:2.3:a:google:gerrit:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://gerrit.googlesource.com/gerrit/+/0532fb876cb86bc091a91f78e6f28fff9e39ca65 | Issue Tracking Patch Vendor Advisory |
| https://www.gerritcodereview.com/2.15.html#21521 | Release Notes Vendor Advisory |
| https://www.gerritcodereview.com/2.16.html#21625 | Release Notes Vendor Advisory |
| https://www.gerritcodereview.com/3.0.html#3014 | Release Notes Vendor Advisory |
| https://www.gerritcodereview.com/3.1.html#3110 | Release Notes Vendor Advisory |
| https://www.gerritcodereview.com/3.2.html#325 | Release Notes Vendor Advisory |