CVE-2020-15767
Summary
| CVE | CVE-2020-15767 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-18 14:15:00 UTC |
| Updated | 2021-12-21 00:47:00 UTC |
| Description | An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a HTTP instead of HTTPS address to access the server. This cookie value could then be used to perform CSRF. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gradle | Enterprise | All | All | All | All |
| Application | Gradle | Enterprise | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories · gradle/gradle · GitHub | MISC | github.com | Third Party Advisory |
| Gradle Enterprise - Security Advisories | Gradle Inc. | CONFIRM | security.gradle.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.