Gradle Enterprise prior to 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gradle gradle |