In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGradle Enterprise
APPGradle< 2018.5.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2023-49238CRITICAL9.8PL ✓same product
Gradle Enterprise — domyślne nieunikalnie hasło użytkownika systemowego umożliwia przejęcie konta
CVE-2022-27919CRITICAL9.8PL ✓same product
RCE w Gradle Enterprise przez brak pliku konfiguracyjnego
CVE-2021-41589CRITICAL9.8PL ✓same product
Cache poisoning i RCE w Gradle Enterprise oraz Build Cache Node
CVE-2019-11403CRITICAL9.8PL ✓same product
Gradle Enterprise — ujawnienie hasła w źródle strony ustawień
CVE-2022-41575HIGH7.5same product
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3...