First published: Fri Sep 24 2021(Updated: )
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gradle Gradle | >=2017.6<2021.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41587 is a vulnerability in Gradle Enterprise before 2021.1.3 that allows an attacker to perform SSRF attacks and potentially discover credentials for other resources.
CVE-2021-41587 has a severity score of 7.5 (high).
CVE-2021-41587 affects Gradle Enterprise versions before 2021.1.3.
An attacker with the ability to perform SSRF attacks can exploit CVE-2021-41587 to potentially discover credentials for other resources.
Yes, you can fix CVE-2021-41587 by updating Gradle Enterprise to version 2021.1.3 or later.