Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-15773 An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an a… Enterprise 2020.2.4+ Fix from $1,6002020-09-18 HIGH 8.8 CVE-2020-15776 An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as Http… Enterprise after 2020.2.4 Fix from $1,9502020-09-18 HIGH 7.5 CVE-2020-15768 An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection … Enterprise after 2020.2.4 Fix from $1,9502020-09-18 HIGH 7.5 CVE-2020-15771 An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF tok… Enterprise Mitigation only Fix from $1,9502020-09-18 HIGH 7.5 CVE-2020-15775 An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as pro… Enterprise after 2020.2.4 Fix from $1,9502020-09-18 MEDIUM 6.8 CVE-2020-15774 An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in … Enterprise after 2020.2.4 Fix from $1,6002020-09-18 MEDIUM 6.1 CVE-2020-15769 An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL. Enterprise after 2020.2.4 Fix from $1,6002020-09-18 MEDIUM 5.5 CVE-2020-15770 An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack… Enterprise Mitigation only Fix from $1,6002020-09-18 MEDIUM 5.3 CVE-2020-15767 An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” … Enterprise 2020.2.5+ Fix from $1,6002020-09-18 HIGH 7.8 CVE-2020-15777 An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Jav… Maven 1.6+ Fix from $1,9502020-08-25 MEDIUM 6.5 CVE-2020-7599 All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publ… Plugin Publishing 0.11.0+ Fix from $1,6002020-03-30 MEDIUM 5.9 CVE-2019-16370 The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one … Gradle 6.0+ Fix from $1,6002019-09-16 CRITICAL 9.8 CVE-2019-15052 The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec… Gradle 5.6+ Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2019-11402 In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. Enterprise 2018.5.3+ Fix from $2,3002019-04-22 CRITICAL 9.8 CVE-2019-11403 In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings … Build Cache Node 5.2 / 2018.5.2+ Fix from $2,3002019-04-22 CRITICAL 9.8 CVE-2016-6199 ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object. Gradle No fix yet Fix from $2,3002017-02-07