Vendor CVEs
Gradle
All CVEs
52 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49238 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2024 | In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an… | ||
| CVE-2022-27919 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2022 | Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API. | ||
| CVE-2021-41589 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user… | ||
| CVE-2019-11403 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2019 | In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page. | ||
| CVE-2019-11402 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2019 | In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. | ||
| CVE-2016-6199 | Cri | 0.64 | 9.8 | 0.05 | Feb 7, 2017 | ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object. | ||
| CVE-2025-27148 | Hig | 0.57 | 8.8 | 0.00 | Feb 25, 2025 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library… | ||
| CVE-2020-15776 | Hig | 0.57 | 8.8 | 0.02 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token,… | ||
| CVE-2025-24858 | Hig | 0.54 | — | 0.00 | Jan 26, 2025 | Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and… | ||
| CVE-2022-25364 | Hig | 0.53 | 8.1 | 0.01 | Mar 17, 2022 | In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute… | ||
| CVE-2021-41588 | Hig | 0.53 | 8.1 | 0.01 | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys. | ||
| CVE-2021-29427 | Hig | 0.52 | 8.0 | 0.01 | Apr 13, 2021 | In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve… | ||
| CVE-2020-15777 | Hig | 0.51 | 7.8 | 0.01 | Aug 25, 2020 | An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus allowing an attacker to achieve code execution via a malicious… | ||
| CVE-2022-41575 | Hig | 0.49 | 7.5 | 0.01 | Oct 21, 2022 | A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3. | ||
| CVE-2022-41574 | Hig | 0.49 | 7.5 | 0.01 | Oct 7, 2022 | An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally… | ||
| CVE-2022-30587 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. | ||
| CVE-2021-41587 | Hig | 0.49 | 7.5 | 0.01 | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources. | ||
| CVE-2021-41586 | Hig | 0.49 | 7.5 | 0.01 | Sep 24, 2021 | In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password. | ||
| CVE-2021-41584 | Hig | 0.49 | 7.5 | 0.01 | Sep 24, 2021 | Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header. | ||
| CVE-2021-32751 | Hig | 0.49 | 7.5 | 0.03 | Jul 20, 2021 | Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user… | ||
| CVE-2020-15775 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously. | ||
| CVE-2020-15771 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation. | ||
| CVE-2020-15768 | Hig | 0.49 | 7.5 | 0.02 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS… | ||
| CVE-2026-22865 | Hig | 0.48 | 7.4 | 0.00 | Jan 16, 2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered… | ||
| CVE-2022-30586 | Hig | 0.47 | 7.2 | 0.01 | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution. | ||
| CVE-2021-41619 | Hig | 0.47 | 7.2 | 0.03 | Oct 27, 2021 | An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup… | ||
| CVE-2023-42445 | Med | 0.44 | 6.8 | 0.01 | Oct 6, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to… | ||
| CVE-2020-15774 | Med | 0.44 | 6.8 | 0.00 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access Gradle Enterprise as that user. | ||
| CVE-2022-31156 | Med | 0.43 | 6.6 | 0.01 | Jul 14, 2022 | Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which… | ||
| CVE-2023-30853 | Hig | 0.42 | 7.6 | 0.00 | Apr 28, 2023 | Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially… | ||
| CVE-2022-27225 | Med | 0.42 | 6.5 | 0.01 | Mar 16, 2022 | Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards… | ||
| CVE-2021-26719 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2021 | A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration… | ||
| CVE-2020-11979 | Hig | 0.42 | 7.5 | 0.08 | Oct 1, 2020 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively… | ||
| CVE-2020-15773 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the… | ||
| CVE-2020-7599 | Med | 0.42 | 6.5 | 0.00 | Mar 30, 2020 | All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this… | ||
| CVE-2020-15769 | Med | 0.40 | 6.1 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL. | ||
| CVE-2020-15770 | Med | 0.36 | 5.5 | 0.00 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins. | ||
| CVE-2021-41590 | Med | 0.35 | 5.3 | 0.01 | Oct 27, 2021 | In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be… | ||
| CVE-2020-15767 | Med | 0.34 | 5.3 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a… | ||
| CVE-2020-15772 | Med | 0.32 | 4.9 | 0.01 | Sep 18, 2020 | An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities… | ||
| CVE-2019-16370 | Med | 0.31 | 5.9 | 0.01 | Sep 16, 2019 | The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900. | ||
| CVE-2021-29429 | Med | 0.26 | 4.0 | 0.00 | Apr 12, 2021 | In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through… | ||
| CVE-2026-25063 | Hig | 0.00 | 7.8 | 0.01 | Jan 29, 2026 | gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and including 9.3.0 that allows arbitrary code execution when a user triggers Bash tab completion in a project containing a malicious… | ||
| CVE-2026-22816 | Hig | 0.00 | 7.4 | 0.00 | Jan 16, 2026 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered… | ||
| CVE-2023-44387 | Low | 0.00 | 3.2 | 0.00 | Oct 5, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting… | ||
| CVE-2023-35947 | Med | 0.00 | 6.9 | 0.01 | Jun 30, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being… | ||
| CVE-2023-35946 | Med | 0.00 | 6.9 | 0.00 | Jun 30, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle… | ||
| CVE-2023-26053 | Med | 0.00 | 6.6 | 0.01 | Mar 2, 2023 | Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a `trusted-key` or… | ||
| CVE-2022-23630 | Hig | 0.00 | 7.5 | 0.01 | Feb 10, 2022 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency… | ||
| CVE-2021-29428 | Hig | 0.00 | 8.8 | 0.01 | Apr 13, 2021 | In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly… |
- risk 0.64cvss 9.8epss 0.01
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an…
- risk 0.64cvss 9.8epss 0.02
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
- risk 0.64cvss 9.8epss 0.02
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user…
- risk 0.64cvss 9.8epss 0.01
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
- risk 0.64cvss 9.8epss 0.01
In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
- risk 0.64cvss 9.8epss 0.05
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
- risk 0.57cvss 8.8epss 0.00
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library…
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token,…
- risk 0.54cvss —epss 0.00
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and…
- risk 0.53cvss 8.1epss 0.01
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute…
- risk 0.53cvss 8.1epss 0.01
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.
- risk 0.52cvss 8.0epss 0.01
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve…
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus allowing an attacker to achieve code execution via a malicious…
- risk 0.49cvss 7.5epss 0.01
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.
- risk 0.49cvss 7.5epss 0.01
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally…
- risk 0.49cvss 7.5epss 0.01
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
- risk 0.49cvss 7.5epss 0.01
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
- risk 0.49cvss 7.5epss 0.01
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
- risk 0.49cvss 7.5epss 0.01
Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
- risk 0.49cvss 7.5epss 0.03
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS…
- risk 0.48cvss 7.4epss 0.00
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered…
- risk 0.47cvss 7.2epss 0.01
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
- risk 0.47cvss 7.2epss 0.03
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup…
- risk 0.44cvss 6.8epss 0.01
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to…
- risk 0.44cvss 6.8epss 0.00
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access Gradle Enterprise as that user.
- risk 0.43cvss 6.6epss 0.01
Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which…
- risk 0.42cvss 7.6epss 0.00
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially…
- risk 0.42cvss 6.5epss 0.01
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards…
- risk 0.42cvss 6.5epss 0.01
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration…
- risk 0.42cvss 7.5epss 0.08
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively…
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the…
- risk 0.42cvss 6.5epss 0.00
All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
- risk 0.35cvss 5.3epss 0.01
In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be…
- risk 0.34cvss 5.3epss 0.01
An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a…
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities…
- risk 0.31cvss 5.9epss 0.01
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
- risk 0.26cvss 4.0epss 0.00
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through…
- risk 0.00cvss 7.8epss 0.01
gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and including 9.3.0 that allows arbitrary code execution when a user triggers Bash tab completion in a project containing a malicious…
- risk 0.00cvss 7.4epss 0.00
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered…
- risk 0.00cvss 3.2epss 0.00
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissions of the linked file to the resulting…
- risk 0.00cvss 6.9epss 0.01
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives, Gradle did not check that files could be written outside of the unpack location. This could lead to important files being…
- risk 0.00cvss 6.9epss 0.00
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With specially crafted dependency coordinates, Gradle…
- risk 0.00cvss 6.6epss 0.01
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) for PGP keys. Users of dependency verification in Gradle are vulnerable if they use long IDs for PGP keys in a `trusted-key` or…
- risk 0.00cvss 7.5epss 0.01
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency…
- risk 0.00cvss 8.8epss 0.01
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly…
Page 1 of 2