Vulnerabilities > Gradle > Enterprise > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-49238 Weak Password Requirements vulnerability in Gradle Enterprise
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password.
network
low complexity
gradle CWE-521
critical
9.8
2022-03-25 CVE-2022-27919 Incorrect Default Permissions vulnerability in Gradle Enterprise
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file.
network
low complexity
gradle CWE-276
critical
9.8
2021-10-27 CVE-2021-41619 Code Injection vulnerability in Gradle Enterprise
An issue was discovered in Gradle Enterprise before 2021.1.2.
network
low complexity
gradle CWE-94
critical
9.0
2019-04-22 CVE-2019-11402 Insufficiently Protected Credentials vulnerability in Gradle Enterprise
In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
network
low complexity
gradle CWE-522
critical
9.8
2019-04-22 CVE-2019-11403 Information Exposure vulnerability in Gradle Build Cache Node and Enterprise
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
network
low complexity
gradle CWE-200
critical
9.8