7.5
CVSSv3

CVE-2021-41584

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: 5 | VMScore: 850 | EPSS: 0.00271 | KEV: Not Included
Published: 24/09/2021 Updated: 21/11/2024

Vulnerability Summary

Gradle Enterprise prior to 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gradle gradle