NA
CVSSv3

CVE-2025-24858

CVSSv4: 8.3 | CVSSv3: NA | CVSSv2: NA | VMScore: 930 | EPSS: 0.00018 | KEV: Not Included
Published: 26/01/2025 Updated: 26/01/2025

Vulnerability Summary

Unauthorized Network Access Reveals Hashed Password in Develocity Servers

Develocity (formerly known as Gradle Enterprise) versions before 2024.3.1 have a vulnerability. An attacker with network access to a Develocity server can get the system user's hashed password. The hash algorithm follows best practices and offers some protection from brute-force attacks. How serious this vulnerability is depends on if the server is accessible by outsiders or unauthorized users, and how complex the system user's password is.

Vulnerable Product Search on Vulmon Subscribe to Product

gradle enterprise