CVE-2020-15770: Medium severity gradle enterprise vulnerability
Published Sep 18, 2020
·Updated
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
Affected Software
1 affected component
Gradle Enterprise=2018.5
Event History
Sep 18, 2020
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15770?
CVE-2020-15770 is a vulnerability discovered in Gradle Enterprise 2018.5 that allows an attacker to potentially guess a local user's password through repeated failed logins without lock-out.
2
What is the severity of CVE-2020-15770?
The severity of CVE-2020-15770 is medium with a severity value of 5.5.
3
How can an attacker exploit CVE-2020-15770?
An attacker can exploit CVE-2020-15770 by making repeated attempts to guess a local user's password without being locked out.
4
What software versions are affected by CVE-2020-15770?
Gradle Enterprise 2018.5 is affected by CVE-2020-15770.
5
How can I fix the CVE-2020-15770 vulnerability?
To fix the CVE-2020-15770 vulnerability, update to a patched version of Gradle Enterprise.