Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.
References
Configurations
No configuration.
History
08 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config. |
06 May 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) or other security impacts via manipulating IPSET_ATTR_CIDR Netlink attribute without proper bounds checking on the modified IP address in bitmap_ip_uadt |
17 Apr 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
17 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
16 Apr 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-16 23:15
Updated : 2025-05-08 20:15
NVD link : CVE-2025-1568
Mitre link : CVE-2025-1568
CVE.ORG link : CVE-2025-1568
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control