Vulnerability Description
An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured installation-administrator contact address, via HTTP access to an accidentally exposed internal endpoint. This is fixed in 2022.3.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gradle | Enterprise | >= 2020.4, < 2022.3.2 |
Related Weaknesses (CWE)
References
- https://security.gradle.comVendor Advisory
- https://security.gradle.com/advisory/2022-12MitigationVendor Advisory
- https://security.gradle.comVendor Advisory
- https://security.gradle.com/advisory/2022-12MitigationVendor Advisory
FAQ
What is CVE-2022-41574?
CVE-2022-41574 is a vulnerability with a CVSS score of 7.5 (HIGH). An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content to the configured in...
How severe is CVE-2022-41574?
CVE-2022-41574 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41574?
Check the references section above for vendor advisories and patch information. Affected products include: Gradle Enterprise.