Metrics
Affected Vendors & Products
Tue, 06 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config. | or other security impacts via manipulating IPSET_ATTR_CIDR Netlink attribute without proper bounds checking on the modified IP address in bitmap_ip_uadt |
Thu, 17 Apr 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 |
Thu, 17 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 | |
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 17 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 | |
Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Gerrit Access Control Vulnerability Allows Malicious Code Injection in ChromeOS |
Wed, 16 Apr 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config. | |
Title | Gerrit Access Control Vulnerability Allows Malicious Code Injection in ChromeOS | |
References |
|

Status: PUBLISHED
Assigner: ChromeOS
Published: 2025-04-16T23:06:28.902Z
Updated: 2025-05-07T19:44:08.491Z
Reserved: 2025-02-21T22:33:59.174Z
Link: CVE-2025-1568

Updated: 2025-04-17T13:28:40.990Z

Status : Awaiting Analysis
Published: 2025-04-16T23:15:44.853
Modified: 2025-05-06T01:15:50.163
Link: CVE-2025-1568

No data.