gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc…
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of…
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso…
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle…
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen…
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl…
Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a …
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai…
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura…
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed…
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During…
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …
In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r…
An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The…
In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation config…
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration deta…
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradl…
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repo…
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downl…
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1…