Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGradle Enterprise
APPGradle2020.4 – 2021.4.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2023-49238CRITICAL9.8PL ✓same product
Gradle Enterprise — domyślne nieunikalnie hasło użytkownika systemowego umożliwia przejęcie konta
CVE-2021-41589CRITICAL9.8PL ✓same product
Cache poisoning i RCE w Gradle Enterprise oraz Build Cache Node
CVE-2019-11402CRITICAL9.8PL ✓same product
Gradle Enterprise: dane uwierzytelniające Build Cache Node przechowywane bez szyfrowania
CVE-2019-11403CRITICAL9.8PL ✓same product
Gradle Enterprise — ujawnienie hasła w źródle strony ustawień
CVE-2022-41575HIGH7.5same product
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3...