CVE-2021-41619

HIGH

Gradle Enterprise >=2020.4 <2021.1.2 - Authenticated Remote Code Execution via JVM Startup Configuration

Title source: llm
STIX 2.1

Description

An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup options. Some of these options, such as -XX:OnOutOfMemoryError, allow specifying a command to be run on the host. This can be abused to run arbitrary commands on the host, should an attacker gain administrative access to the application.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://security.gradle.com
Vendor Advisory x_refsource_misc
https://security.gradle.com/advisory/2021-08

Scores

CVSS v3 7.2
EPSS 0.0263
EPSS Percentile 83.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
gradle/enterprise 2020.4 - 2021.1.2
Published Oct 27, 2021
Tracked Since Feb 18, 2026