CVE-2022-25364: Critical severity gradle enterprise vulnerability
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build. As of 2021.4.2, the built-in build cache is inaccessible-by-default, requiring explicit configuration of its access-control settings before it can be used. (Remote build cache nodes are unaffected as they are inaccessible-by-default.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25364?
CVE-2022-25364 is a vulnerability in Gradle Enterprise before version 2021.4.2 that allows anonymous write access to the default built-in build cache configuration.
How can a malicious actor exploit CVE-2022-25364?
A malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of the build process.
How can I check if my Gradle Enterprise version is affected by CVE-2022-25364?
If your Gradle Enterprise version is before 2021.4.2, it is affected by CVE-2022-25364.
Is there a fix available for CVE-2022-25364?
Yes, the fix for CVE-2022-25364 is included in version 2021.4.2 of Gradle Enterprise.
What is the severity of CVE-2022-25364?
CVE-2022-25364 has a severity rating of 8.1, which is categorized as critical.