Unauthorized Network Access Reveals Hashed Password in Develocity Servers
Develocity (formerly known as Gradle Enterprise) versions before 2024.3.1 have a vulnerability. An attacker with network access to a Develocity server can get the system user's hashed password. The hash algorithm follows best practices and offers some protection from brute-force attacks. How serious this vulnerability is depends on if the server is accessible by outsiders or unauthorized users, and how complex the system user's password is.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gradle enterprise |