CVE-2019-11403

CRITICAL

Gradle Enterprise <2018.5.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://gradle.com/enterprise/releases/2018.5/#changes-2
Vendor Advisory x_refsource_confirm
https://security.gradle.com/advisory/CVE-2019-11403

Scores

CVSS v3 9.8
EPSS 0.0118
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (2)
gradle/build_cache_node < 5.2
gradle/enterprise < 2018.5.2
Published Apr 22, 2019
Tracked Since Feb 18, 2026