Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise MEDIUM 6.5
CVE-2020-15773

An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an a…

Fix: 2020.2.4+
Fix from $1,600 2020-09-18
Enterprise HIGH 8.8
CVE-2020-15776

An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as Http…

Fix: after 2020.2.4
Fix from $1,950 2020-09-18
Enterprise HIGH 7.5
CVE-2020-15768

An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection …

Fix: after 2020.2.4
Fix from $1,950 2020-09-18
Enterprise HIGH 7.5
CVE-2020-15771

An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF tok…

Mitigation only
Fix from $1,950 2020-09-18
Enterprise HIGH 7.5
CVE-2020-15775

An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as pro…

Fix: after 2020.2.4
Fix from $1,950 2020-09-18
Enterprise MEDIUM 6.8
CVE-2020-15774

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in …

Fix: after 2020.2.4
Fix from $1,600 2020-09-18
Enterprise MEDIUM 6.1
CVE-2020-15769

An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL.

Fix: after 2020.2.4
Fix from $1,600 2020-09-18
Enterprise MEDIUM 5.5
CVE-2020-15770

An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack…

Mitigation only
Fix from $1,600 2020-09-18
Enterprise MEDIUM 5.3
CVE-2020-15767

An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” …

Fix: 2020.2.5+
Fix from $1,600 2020-09-18
Maven HIGH 7.8
CVE-2020-15777

An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Jav…

Fix: 1.6+
Fix from $1,950 2020-08-25
Plugin Publishing MEDIUM 6.5
CVE-2020-7599

All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publ…

Fix: 0.11.0+
Fix from $1,600 2020-03-30
Gradle MEDIUM 5.9
CVE-2019-16370

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one …

Fix: 6.0+
Fix from $1,600 2019-09-16
Gradle CRITICAL 9.8
CVE-2019-15052

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…

Fix: 5.6+
Fix from $2,300 2019-08-14
Enterprise CRITICAL 9.8
CVE-2019-11402

In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.

Fix: 2018.5.3+
Fix from $2,300 2019-04-22
Build Cache Node CRITICAL 9.8
CVE-2019-11403

In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings …

Fix: 5.2 / 2018.5.2+
Fix from $2,300 2019-04-22
Gradle CRITICAL 9.8
CVE-2016-6199

ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.

No fix yet
Fix from $2,300 2017-02-07