CVE-2020-15773

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/09/2020
Last modified:
25/09/2020

Description

An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gradle:enterprise:*:*:*:*:*:*:*:* 2020.2.4 (excluding)