VYPR
Vendor

Gradle

Products
18
CVEs
52
Across products
90
Status
Private

Products

18

Recent CVEs

52
View all 52 CVEs →
  • CVE-2023-49238CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an…

  • CVE-2022-27919CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.

  • CVE-2021-41589CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user…

  • CVE-2019-11403CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.

  • CVE-2019-11402CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.

  • CVE-2016-6199CriFeb 7, 2017
    risk 0.64cvss 9.8epss 0.05

    ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.

  • CVE-2025-27148HigFeb 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library…

  • CVE-2020-15776HigSep 18, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token,…

  • CVE-2025-24858HigJan 26, 2025
    risk 0.54cvss epss 0.00

    Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and…

  • CVE-2022-25364HigMar 17, 2022
    risk 0.53cvss 8.1epss 0.01

    In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute…

  • CVE-2021-41588HigSep 24, 2021
    risk 0.53cvss 8.1epss 0.01

    In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

  • CVE-2021-29427HigApr 13, 2021
    risk 0.52cvss 8.0epss 0.01

    In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve…

  • CVE-2020-15777HigAug 25, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus allowing an attacker to achieve code execution via a malicious…

  • CVE-2022-41575HigOct 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.

  • CVE-2022-41574HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally…

  • CVE-2022-30587HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.

  • CVE-2021-41587HigSep 24, 2021
    risk 0.49cvss 7.5epss 0.01

    In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.

  • CVE-2021-41586HigSep 24, 2021
    risk 0.49cvss 7.5epss 0.01

    In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.

  • CVE-2021-41584HigSep 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.

  • CVE-2021-32751HigJul 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user…