An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://github.com/gradle/gradle/security/advisories | third party advisory |
https://security.gradle.com/advisory/CVE-2020-15771 | vendor advisory |