CVE-2022-30587: High severity gradle enterprise vulnerability
Published Jun 6, 2022
·Updated
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
Affected Software
1 affected component
Gradle Gradle Enterprise<2022.2.3
Event History
Jun 6, 2022
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
Description
Frequently Asked Questions
1
What is CVE-2022-30587?
CVE-2022-30587 is a vulnerability in Gradle Enterprise through 2022.2.2 that allows incorrect access control, leading to information disclosure.
2
How severe is CVE-2022-30587?
CVE-2022-30587 has a severity rating of 7.5, which is considered high.
3
What is the affected software for CVE-2022-30587?
The affected software for CVE-2022-30587 is Gradle Enterprise through 2022.2.2.
4
How can the vulnerability in CVE-2022-30587 be exploited?
The vulnerability in CVE-2022-30587 can be exploited through incorrect access control, allowing an attacker to disclose sensitive information.
5
How can I fix CVE-2022-30587?
To fix CVE-2022-30587, it is recommended to update Gradle Enterprise to version 2022.2.3 or a later version.