CVE-2021-26719: Path Traversal
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26719?
CVE-2021-26719 is a directory traversal vulnerability discovered in Gradle gradle-enterprise-test-distribution-agent, test-distribution-gradle-plugin, and gradle-enterprise-maven-extension.
How severe is CVE-2021-26719?
CVE-2021-26719 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2021-26719?
Versions before 1.3.2 of Gradle gradle-enterprise-test-distribution-agent and test-distribution-gradle-plugin, and versions before 1.8.2 of gradle-enterprise-maven-extension are affected.
How can a malicious actor exploit CVE-2021-26719?
A malicious actor with certain credentials can perform a registration step to exploit the vulnerability.
Where can I find more information about CVE-2021-26719?
More information about CVE-2021-26719 can be found at the following reference link: https://security.gradle.com/advisory/CVE-2021-26719