CVE-2020-15773: Medium severity gradle enterprise vulnerability
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15773?
CVE-2020-15773 is a vulnerability in Gradle Enterprise before version 2020.2.4 that allows unrestricted cross-origin requests to read-only data in the Export API.
How severe is CVE-2020-15773?
CVE-2020-15773 has a severity score of 6.5 (medium).
What is the affected software?
The affected software is Gradle Enterprise version up to and excluding 2020.2.4.
What is the CWE of CVE-2020-15773?
The CWE of CVE-2020-15773 is CWE-346.
How can the vulnerability be exploited?
An attacker can exploit this vulnerability by making unrestricted cross-origin requests to read-only data in the Export API, allowing them to access data as a user after authenticating with the API.