First published: Fri Sep 24 2021(Updated: )
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gradle Gradle | >=2020.4<2021.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41586 is a vulnerability in Gradle Enterprise before 2021.1.3 that allows an attacker to perform SSRF attacks and potentially reset the system user password.
CVE-2021-41586 has a severity rating of 7.5 (high).
Gradle Enterprise versions before 2021.1.3 are affected by CVE-2021-41586.
An attacker with the ability to perform SSRF attacks can exploit CVE-2021-41586 to potentially reset the system user password.
Yes, upgrading to Gradle Enterprise version 2021.1.3 or later fixes CVE-2021-41586.