Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xcg-cx52-vr25

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. Because of implicitly remembered user-login information, physically proximate attackers can use a user session after browser closure.

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. Because of implicitly remembered user-login information, physically proximate attackers can use a user session after browser closure.

EPSS

Процентиль: 17%
0.00054
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.8
nvd
больше 5 лет назад

An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access Gradle Enterprise as that user.

EPSS

Процентиль: 17%
0.00054
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-613