CVE-2021-41587: SSRF
Published Sep 24, 2021
·Updated
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
Affected Software
1 affected component
gradle Gradle>=2017.6<2021.1.3
Event History
Sep 24, 2021
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-41587?
CVE-2021-41587 is a vulnerability in Gradle Enterprise before 2021.1.3 that allows an attacker to perform SSRF attacks and potentially discover credentials for other resources.
2
How severe is CVE-2021-41587?
CVE-2021-41587 has a severity score of 7.5 (high).
3
How does CVE-2021-41587 affect Gradle Enterprise?
CVE-2021-41587 affects Gradle Enterprise versions before 2021.1.3.
4
How can an attacker exploit CVE-2021-41587?
An attacker with the ability to perform SSRF attacks can exploit CVE-2021-41587 to potentially discover credentials for other resources.
5
Is there a fix for CVE-2021-41587?
Yes, you can fix CVE-2021-41587 by updating Gradle Enterprise to version 2021.1.3 or later.