PT-2022-25948 · Gradle · Gradle Enterprise

Published

2022-10-21

·

Updated

2022-10-24

·

CVE-2022-41575

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gradle Enterprise versions 2022.3 through 2022.3.3
Description A credential-exposure issue in the support-bundle mechanism allows remote attackers to access a subset of application data, including cleartext credentials.
Recommendations For Gradle Enterprise versions 2022.3 through 2022.3.3, update to version 2022.3.3 or later to resolve the issue.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-41575

Affected Products

Gradle Enterprise