Beveiligingsadvies

CVE-2026-2725

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-13 05:32:49
Laatst bijgewerkt 2026-07-06 23:17:51
Toegewezen door Google
CVSS-score 6.0
Status PUBLISHED

Beschrijving

Incorrect authorization in the "submitted together" feature in Gerrit versions 2.12 and later allows an authenticated attacker with force push permissions on a secondary branch to bypass code review and forcefully submit code to restricted branches via a crafted submission matching the "topic" tag of an unapproved change.