CVE-2022-41575: High severity Gradle Enterprise vulnerability
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gradle Enterpriseto a version that resolves this vulnerability.Fixed in 2022.3.3
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-41575.
What is the severity of CVE-2022-41575?
The severity of CVE-2022-41575 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2022-41575?
Versions of Gradle Enterprise 2022.3 through 2022.3.3 are affected by CVE-2022-41575.
How can remote attackers exploit CVE-2022-41575?
Remote attackers can exploit CVE-2022-41575 by accessing a subset of application data, such as cleartext credentials, through the support-bundle mechanism in Gradle Enterprise.
How do I fix CVE-2022-41575?
To fix CVE-2022-41575, upgrade to version 2022.3.3 of Gradle Enterprise.