Projects and repositories managed by Google's Gerrit Code Review system allowed for a supply chain attack due to excessive default permissions and a logic flaw in the code review process workflow. For projects with vulnerable configurations in place, attackers could have potentially injected malicious code into trusted build pipelines.