PT-2026-98310 · Unknown · Gerrit Code Review
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gerrit Code Review versions 2.16.0 through 3.12.9
Gerrit Code Review versions 3.13.0 through 3.13.8
Gerrit Code Review versions 3.14.0 through 3.14.2
Description
Incorrect authorization occurs during project name normalization in
ProjectUtil.stripGitSuffix() and project cache eviction in ProjectCacheImpl. An authenticated user, or an unauthenticated user if the repository was previously public, can cause unauthorized disclosure of private repository content and restore revoked project-owner administrative privileges. This is achieved through crafted requests using repeated .git suffixes (e.g., project.git.git) across REST APIs, Gitiles, or SSH Git commands. The issue arises because the system strips only a single terminal .git suffix when creating the logical ProjectCache key, while JGit resolves the suffixed alias to the same canonical bare repository on disk. Consequently, revoking read access or removing owner rules on the canonical project name fails to evict the cached alias ProjectState during the cache validity window, allowing reads of private commits or writes to refs/meta/config.Recommendations
Update Gerrit Code Review versions 2.16.0 through 3.12.9 to version 3.12.10.
Update Gerrit Code Review versions 3.13.0 through 3.13.8 to version 3.13.9.
Update Gerrit Code Review versions 3.14.0 through 3.14.2 to version 3.14.3.
Exploit
Fix
Incorrect Authorization
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gerrit Code Review