VYPR

Gradle

by Gradle

Source repositories

CVEs (26)

  • CVE-2023-35946MedJun 30, 2023
    risk 0.00cvss 6.9epss 0.00

    Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle…

  • CVE-2023-26053MedMar 2, 2023
    risk 0.00cvss 6.6epss 0.01

    Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a `trusted-key` or…

  • CVE-2022-23630HigFeb 10, 2022
    risk 0.00cvss 7.5epss 0.01

    Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency…

  • CVE-2021-29428HigApr 13, 2021
    risk 0.00cvss 8.8epss 0.01

    In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly…

  • CVE-2019-15052CriAug 14, 2019
    risk 0.00cvss 9.8epss 0.03

    The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

  • CVE-2019-11065MedApr 10, 2019
    risk 0.00cvss 5.9epss 0.01

    Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

Page 2 of 2