CVE-2021-29429Medium· 4.0▾ SunlitIn Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remo…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the TextResourceFactory API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property java.io.tmpdir. The new path needs to limit permissions to the build user only.
gradle < 7.0quarkus <= 2.2.3Upgrade past the affected range:
gradle 7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29428High· 8.8In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it
CVE-2023-44387Low· 3.2Gradle is a build tool with a focus on build automation and support for multi-language development
CVE-2023-35946Medium· 6.9Gradle is a build tool with a focus on build automation and support for multi-language development
CVE-2021-32751High· 7.5Gradle is a build tool with a focus on build automation
CVE-2026-106451High· 7.3yawkat LZ4 Java provides LZ4 compression for Java
CVE-2026-79899High· 7.9Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert