PT-2022-17242 · Gradle · Gradle Enterprise

Published

2022-03-17

·

Updated

2023-08-08

·

CVE-2022-25364

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gradle Enterprise versions prior to 2021.4.2
Description The default built-in build cache configuration in Gradle Enterprise allowed anonymous write access, potentially enabling a malicious actor with network access to populate the cache with manipulated entries that execute malicious code as part of a build. As of version 2021.4.2, the built-in build cache is inaccessible by default and requires explicit configuration of its access-control settings before use.
Recommendations For versions prior to 2021.4.2, update to version 2021.4.2 or later to ensure the built-in build cache is inaccessible by default and requires explicit configuration of its access-control settings. As a temporary workaround, consider restricting access to the build cache to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-25364

Affected Products

Gradle Enterprise