Vulnerabilities > Gradle > Enterprise > 2022.3.1

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-49238 Weak Password Requirements vulnerability in Gradle Enterprise
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password.
network
low complexity
gradle CWE-521
critical
9.8
2022-10-21 CVE-2022-41575 Insufficiently Protected Credentials vulnerability in Gradle Enterprise 2022.3.1/2022.3.2
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials).
network
low complexity
gradle CWE-522
7.5
2022-10-07 CVE-2022-41574 Incorrect Authorization vulnerability in Gradle Enterprise
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally exposed internal endpoint.
network
low complexity
gradle CWE-863
7.5