Executive brief
Gerrit, a web-based code review tool, contains a vulnerability in its 'submitted together' feature. An authorized user with specific permissions on a secondary branch can bypass the standard code review process to forcefully submit unapproved code into restricted branches. This could allow unauthorized changes to be merged into a software project's main codebase, potentially compromising the integrity of the software.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the 'submitted together' feature of Gerrit versions 2.12 and later. The flaw is triggered when an authenticated attacker has 'force push' permissions on at least one secondary branch. By crafting a submission that matches the 'topic' tag of an existing unapproved change, the attacker can exploit the logic that groups changes for submission. This allows the attacker to bypass mandatory code review requirements and merge code into restricted branches. A patch is available in the Gerrit issue tracker.
Affected products
- Google Gerrit 2.12 and later
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory