VYPR

Gradle Enterprise

by Gradle

CVEs (24)

  • CVE-2020-15770MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.

  • CVE-2021-41590MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.01

    In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be…

  • CVE-2020-15767MedSep 18, 2020
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a…

  • CVE-2020-15772MedSep 18, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities…

Page 2 of 2