VulnSea

gradle vulnerabilities

CVEs whose affected-version data names the gradle package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2023-44387Low· 3.2
3y ago

Gradle is a build tool with a focus on build automation and support for multi-language development

Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle resolves them but applies the permissions of the symlink itself instead of the permissi…

▾ Sunlitgradle · gradleEPSS 0.22%via NVD
CVE-2023-35946Medium· 6.9
3y ago

Gradle is a build tool with a focus on build automation and support for multi-language development

Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a dependency into its dependency cache, it uses the dependency's coordinates to compute a file location. With speciall…

▾ Sunlitgradle · gradleEPSS 0.28%via NVD
CVE-2021-32751High· 7.5
5y ago

Gradle is a build tool with a focus on build automation

Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to c…

▾ Twilightgradle · gradleEPSS 2.7%via NVD
CVE-2021-29428High· 8.8
5y ago

In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it

In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privileg…

▾ Twilightgradle · gradleEPSS 0.54%via NVD
CVE-2021-29429Medium· 4.0
5y ago

In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle

In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remo…

▾ Sunlitgradle · gradleEPSS 0.48%via NVD
CVE-2020-11979High· 7.5
6y ago

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new…

▾ Twilightapache · antEPSS 8.0%via NVD
gradle vulnerabilities (CVEs) · VulnSea