Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7599

Опубликовано: 30 мар. 2020
Источник: nvd
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this build log is publicly visible (as it is in many popular public CI systems like TravisCI) this AWS pre-signed URL would allow a malicious actor to replace a recently uploaded plugin with their own.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gradle:plugin_publishing:*:*:*:*:*:*:*:*
Версия до 0.11.0 (исключая)

EPSS

Процентиль: 40%
0.00181
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Exposure of Sensitive Information in Gradle publish plugin

EPSS

Процентиль: 40%
0.00181
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-532