Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cj4-x7wr-qf2p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. There is XXE with resultant SSRF via an uploaded SAML IDP configuration.

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. There is XXE with resultant SSRF via an uploaded SAML IDP configuration.

EPSS

Процентиль: 46%
0.00235
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 4.9
nvd
больше 5 лет назад

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities (XXE), allowing a remote attacker with administrative access to perform server side request forgery.

EPSS

Процентиль: 46%
0.00235
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611