rpm package
suse/gradle&distro=SUSE Linux Enterprise Module for Development Tools 15 SP5
pkg:rpm/suse/gradle&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-35946 | — | < 4.4.1-150200.3.24.1 | 4.4.1-150200.3.24.1 | Jun 30, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle ca | ||
| CVE-2023-35947 | — | < 4.4.1-150200.3.27.1 | 4.4.1-150200.3.27.1 | Jun 30, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being overwrit | ||
| CVE-2021-29429 | — | < 4.4.1-150200.3.15.1 | 4.4.1-150200.3.15.1 | Apr 12, 2021 | In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFacto | ||
| CVE-2019-15052 | — | < 4.4.1-150200.3.15.1 | 4.4.1-150200.3.15.1 | Aug 14, 2019 | The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007. |
- CVE-2023-35946Jun 30, 2023affected < 4.4.1-150200.3.24.1fixed 4.4.1-150200.3.24.1
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle ca
- CVE-2023-35947Jun 30, 2023affected < 4.4.1-150200.3.27.1fixed 4.4.1-150200.3.27.1
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being overwrit
- CVE-2021-29429Apr 12, 2021affected < 4.4.1-150200.3.15.1fixed 4.4.1-150200.3.15.1
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFacto
- CVE-2019-15052Aug 14, 2019affected < 4.4.1-150200.3.15.1fixed 4.4.1-150200.3.15.1
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.