In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGradle Build Cache Node
APPGradle< 5.2Gradle Enterprise
APPGradle< 2018.5.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2023-49238CRITICAL9.8PL ✓same product
Gradle Enterprise — domyślne nieunikalnie hasło użytkownika systemowego umożliwia przejęcie konta
CVE-2022-27919CRITICAL9.8PL ✓same product
RCE w Gradle Enterprise przez brak pliku konfiguracyjnego
CVE-2021-41589CRITICAL9.8PL ✓same product
Cache poisoning i RCE w Gradle Enterprise oraz Build Cache Node
CVE-2019-11402CRITICAL9.8PL ✓same product
Gradle Enterprise: dane uwierzytelniające Build Cache Node przechowywane bez szyfrowania
CVE-2022-41575HIGH7.5same product
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3...