Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j29-824j-4f3v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

EPSS

Процентиль: 42%
0.00194
Низкий

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.

EPSS

Процентиль: 42%
0.00194
Низкий

Дефекты

CWE-502