QID 730707
QID 730707: Gradle Enterprise Remote Code Execution (RCE) Vulnerability
Gradle Enterprise leverages acceleration technologies to speed up the software build and test process and data analytics to make troubleshooting more efficient.
Affected Versions:
Gradle Enterprise v2020.4 to v2021.4.3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sending a GET request to non-existent endpoint.
Allows a malicious user to perform Remote Code Execution.
Solution
Customers are advised to upgrade to Gradle Enterprise v2022.1 or later to remediate these vulnerabilities.
Vendor References
- CVE-2022-27919 -
security.gradle.com/advisory/2022-05
CVEs related to QID 730707
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-27919 |
|