CVE-2021-41584: High severity gradle Gradle vulnerability
Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gradle Enterpriseto a version that resolves this vulnerability.Fixed in 2021.1.3 - Compensating control
Mitigate by preventing access to the Gradle Enterprise HTTP endpoint(s) that accept the crafted request; restrict/limit exposure of the service at the network layer (e.g., firewall/ACL) so only authorized clients can reach it.
Event History
Frequently Asked Questions
What is CVE-2021-41584?
CVE-2021-41584 is a vulnerability in Gradle Enterprise before version 2021.1.3 that can allow unauthorized viewing of a response, resulting in information disclosure of potentially sensitive build and configuration details.
How does CVE-2021-41584 impact Gradle Enterprise?
CVE-2021-41584 allows unauthorized users to view responses, potentially exposing sensitive build and configuration information in Gradle Enterprise.
What is the severity of CVE-2021-41584?
CVE-2021-41584 has a severity rating of high (7.5).
How can I fix CVE-2021-41584?
To fix CVE-2021-41584, upgrade Gradle Enterprise to version 2021.1.3 or newer.
Where can I find more information about CVE-2021-41584?
More information about CVE-2021-41584 can be found at the following URL: https://security.gradle.com/advisory/2021-02