First published: Fri Sep 18 2020(Updated: )
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gradle Enterprise | =2018.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15770 is a vulnerability discovered in Gradle Enterprise 2018.5 that allows an attacker to potentially guess a local user's password through repeated failed logins without lock-out.
The severity of CVE-2020-15770 is medium with a severity value of 5.5.
An attacker can exploit CVE-2020-15770 by making repeated attempts to guess a local user's password without being locked out.
Gradle Enterprise 2018.5 is affected by CVE-2020-15770.
To fix the CVE-2020-15770 vulnerability, update to a patched version of Gradle Enterprise.