Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.
References
Link | Resource |
---|---|
https://security.gradle.com/advisory/2022-05 | Mitigation Vendor Advisory |
Configurations
Information
Published : 2022-03-25 13:15
Updated : 2022-03-30 12:08
NVD link : CVE-2022-27919
Mitre link : CVE-2022-27919
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
gradle
- enterprise