Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-25063 gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc… Gradle Completion after 9.3.0 Fix from $1,9502026-01-29 HIGH 7.4 CVE-2026-22816 Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor… Gradle 8.14.4 / 9.3.0+ Fix from $1,9502026-01-16 HIGH 7.4 CVE-2026-22865 Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor… Gradle 8.14.4 / 9.3.0+ Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2023-49238 In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of… Enterprise 2023.1+ Fix from $2,3002024-01-09 MEDIUM 5.3 CVE-2023-42445 Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso… Gradle 7.6.3 / 8.4.0+ Fix from $1,6002023-10-06 MEDIUM 6.5 CVE-2023-44387 Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle… Gradle 7.6.3 / 8.4.0+ Fix from $1,6002023-10-05 HIGH 8.1 CVE-2023-35947 Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,… Gradle 7.6.2 / 8.2.0+ Fix from $1,9502023-06-30 MEDIUM 5.5 CVE-2023-35946 Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependen… Gradle 7.6.2 / 8.2.0+ Fix from $1,6002023-06-30 MEDIUM 6.5 CVE-2023-30853 Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradl… Build Action 2.4.2+ Fix from $1,6002023-04-28 CRITICAL 9.8 CVE-2023-26053 Gradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f… Gradle 6.9.4 / 7.6.1+ Fix from $2,3002023-03-02 HIGH 7.5 CVE-2022-41575 A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a … Enterprise 2022.3.3+ Fix from $1,9502022-10-21 HIGH 7.5 CVE-2022-41574 An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emai… Enterprise 2022.3.2+ Fix from $1,9502022-10-07 HIGH 7.5 CVE-2022-30587 Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. Gradle Enterprise 2022.2.3+ Fix from $1,9502022-06-06 HIGH 7.2 CVE-2022-30586 Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution. Gradle 1.3.1+ Fix from $1,9502022-06-06 CRITICAL 9.8 CVE-2022-27919 Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura… Enterprise after 2021.4.3 Fix from $2,3002022-03-25 HIGH 8.1 CVE-2022-25364 In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed… Enterprise 2021.4.2+ Fix from $1,9502022-03-17 MEDIUM 6.5 CVE-2022-27225 Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During… Enterprise 2021.4.3+ Fix from $1,6002022-03-16 HIGH 7.5 CVE-2022-23630 Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification … Gradle after 7.3.3 Fix from $1,9502022-02-10 CRITICAL 9.8 CVE-2021-41589 In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r… Build Cache Node 10.0 / 2021.3+ Fix from $2,3002021-10-27 HIGH 7.2 CVE-2021-41619 An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The… Enterprise 2021.1.2+ Fix from $1,9502021-10-27 MEDIUM 5.3 CVE-2021-41590 In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation config… Enterprise 2021.3+ Fix from $1,6002021-10-27 HIGH 8.1 CVE-2021-41588 In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr… Gradle 2021.1.3+ Fix from $1,9502021-09-24 HIGH 7.5 CVE-2021-41586 In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password. Gradle 2021.1.3+ Fix from $1,9502021-09-24 HIGH 7.5 CVE-2021-41587 In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources. Gradle 2021.1.3+ Fix from $1,9502021-09-24 HIGH 7.5 CVE-2021-41584 Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration deta… Gradle 2021.1.3+ Fix from $1,9502021-09-24 HIGH 7.5 CVE-2021-32751 Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradl… Gradle 7.2+ Fix from $1,9502021-07-20 HIGH 7.8 CVE-2021-29428 In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to … Gradle 7.0+ Fix from $1,9502021-04-13 HIGH 7.2 CVE-2021-29427 In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repo… Gradle 7.0+ Fix from $1,9502021-04-13 MEDIUM 5.5 CVE-2021-29429 In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downl… Gradle 7.0+ Fix from $1,6002021-04-12 MEDIUM 6.5 CVE-2021-26719 A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1… Enterprise Test Distribution Agent 1.3.2+ Fix from $1,6002021-02-09