Vulnerabilities > Gradle > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2023-49238 Weak Password Requirements vulnerability in Gradle Enterprise
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password.
network
low complexity
gradle CWE-521
critical
9.8
2023-03-02 CVE-2023-26053 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Gradle
Gradle is a build tool with a focus on build automation and support for multi-language development.
network
low complexity
gradle CWE-829
critical
9.8
2022-03-25 CVE-2022-27919 Incorrect Default Permissions vulnerability in Gradle Enterprise
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file.
network
low complexity
gradle CWE-276
critical
9.8
2021-10-27 CVE-2021-41619 Code Injection vulnerability in Gradle Enterprise
An issue was discovered in Gradle Enterprise before 2021.1.2.
network
low complexity
gradle CWE-94
critical
9.0
2019-08-14 CVE-2019-15052 Insufficiently Protected Credentials vulnerability in Gradle
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host.
network
low complexity
gradle CWE-522
critical
9.8
2019-04-22 CVE-2019-11403 Information Exposure vulnerability in Gradle Build Cache Node and Enterprise
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
network
low complexity
gradle CWE-200
critical
9.8
2019-04-22 CVE-2019-11402 Insufficiently Protected Credentials vulnerability in Gradle Enterprise
In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.
network
low complexity
gradle CWE-522
critical
9.8