Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2725

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.

A flaw was found in Gerrit. An authenticated attacker with force push permissions on a secondary branch can exploit an incorrect authorization vulnerability within the "submitted together" feature. By crafting a submission that matches the "topic" tag of an unapproved change, the attacker can bypass code review. This allows them to forcefully submit code to restricted branches, potentially leading to unauthorized changes in the codebase.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Fuse 7gerrit-apiNot affected
Self-service automation portal 2ansible-automation-platform/automation-portalNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2476938gerrit: Gerrit: Code review bypass via incorrect authorization

EPSS

Процентиль: 2%
0.00116
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.

CVSS3: 5.3
debian
3 месяца назад

Incorrect authorization in the "submitted together" feature in Gerrit ...

CVSS3: 5.3
github
3 месяца назад

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.

EPSS

Процентиль: 2%
0.00116
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-2725