CVE-2021-41588: High severity gradle Gradle vulnerability
Published Sep 24, 2021
·Updated
In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.
Affected Software
1 affected component
gradle Gradle>=2017.2<2021.1.3
Event History
Sep 24, 2021
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-41588?
CVE-2021-41588 is a vulnerability in Gradle Enterprise before 2021.1.3 that allows a crafted request to trigger deserialization of arbitrary unsafe Java objects.
2
How severe is CVE-2021-41588?
CVE-2021-41588 has a severity rating of 8.1 (High).
3
How does CVE-2021-41588 affect Gradle Enterprise?
CVE-2021-41588 affects Gradle Enterprise versions before 2021.1.3.
4
What are the affected versions of Gradle Enterprise?
Gradle Enterprise versions between 2017.2 and 2021.1.2 are affected by CVE-2021-41588.
5
Is authentication required to exploit CVE-2021-41588?
Yes, the attacker must have the encryption and signing keys to exploit CVE-2021-41588.