CVE-2020-15776: CSRF
Published Sep 18, 2020
·Updated
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token, allowing them to perform cross-site request forgery.
Affected Software
1 affected component
Gradle Enterprise>=2018.2<=2020.2.4
Event History
Sep 18, 2020
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15776?
The severity of CVE-2020-15776 is high (8.8).
2
What is the impact of CVE-2020-15776?
CVE-2020-15776 allows an attacker to impose an arbitrary value for the CSRF prevention token, potentially leading to unauthorized actions.
3
Which version of Gradle Enterprise is affected by CVE-2020-15776?
Gradle Enterprise versions 2018.2 through 2020.2.4 are affected by CVE-2020-15776.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-15776?
The CWE ID for CVE-2020-15776 is CWE-352 and CWE-732.
5
How can I fix CVE-2020-15776?
To fix CVE-2020-15776, update Gradle Enterprise to a version higher than 2020.2.4.