First published: Sun Apr 21 2019(Updated: )
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gradle Build Cache Node | <5.2 | |
Gradle Enterprise | <2018.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11403 is a vulnerability in Gradle Enterprise before version 2018.5.2 that allows the configured password to be reflected back when viewing the HTML page source of the settings page.
CVE-2019-11403 affects Gradle Build Cache Node versions up to but excluding 5.2.
CVE-2019-11403 affects Gradle Enterprise versions up to but excluding 2018.5.2.
CVE-2019-11403 has a severity rating of 9.8 (critical).
To fix CVE-2019-11403, update Gradle Build Cache Node to version 5.2 or higher, or update Gradle Enterprise to version 2018.5.2 or higher.