QID 730707

QID 730707: Gradle Enterprise Remote Code Execution (RCE) Vulnerability

Gradle Enterprise leverages acceleration technologies to speed up the software build and test process and data analytics to make troubleshooting more efficient.

Affected Versions:
Gradle Enterprise v2020.4 to v2021.4.3

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sending a GET request to non-existent endpoint.

Allows a malicious user to perform Remote Code Execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Gradle Enterprise v2022.1 or later to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 730707

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-27919 URL Logo security.gradle.com/advisory/2022-05