Vulnerabilities > Gradle > Gradle

DATE CVE VULNERABILITY TITLE RISK
2021-09-24 CVE-2021-41588 Deserialization of Untrusted Data vulnerability in Gradle
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects.
network
gradle CWE-502
6.8
2021-09-24 CVE-2021-41584 Information Exposure vulnerability in Gradle
Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
network
low complexity
gradle CWE-200
5.0
2021-07-20 CVE-2021-32751 OS Command Injection vulnerability in Gradle
Gradle is a build tool with a focus on build automation.
network
gradle CWE-78
8.5
2021-04-13 CVE-2021-29428 Creation of Temporary File in Directory with Incorrect Permissions vulnerability in multiple products
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it.
4.4
2021-04-13 CVE-2021-29427 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning.
6.0
2021-04-12 CVE-2021-29429 Insecure Temporary File vulnerability in multiple products
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle.
1.9
2020-10-01 CVE-2020-11979 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them.
network
low complexity
apache gradle fedoraproject oracle
7.5
2019-09-16 CVE-2019-16370 Improper Input Validation vulnerability in Gradle
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
network
gradle CWE-20
4.3
2019-08-14 CVE-2019-15052 Insufficiently Protected Credentials vulnerability in Gradle
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host.
network
low complexity
gradle CWE-522
critical
9.8
2019-04-10 CVE-2019-11065 Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used.
network
high complexity
gradle fedoraproject
5.9