Gradle是美国Gradle公司的一套基于JVM的项目构建工具,它支持maven、Ivy仓库等。 Gradle Enterprise 在 2021.4.2 之前存在安全漏洞,该漏洞源于默认的内置构建缓存配置允许匿名写访问。如果不手动更改此设置,则对构建缓存具有网络访问权限的恶意行为者可能会在其中填充受操纵的条目,这些条目在构建过程中执行恶意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0748 | 9.8 CRITICAL | Arbitrary Code Execution |
| CVE-2022-25354 | 8.6 HIGH | Prototype Pollution |
| CVE-2022-25352 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-0749 | 7.4 HIGH | Deserialization of Untrusted Data |
| CVE-2022-25760 | 7.1 HIGH | Arbitrary Code Injection |
| CVE-2021-23632 | 6.6 MEDIUM | Remote Code Execution (RCE) |
| CVE-2021-23771 | 6.5 MEDIUM | Sandbox Bypass |
| CVE-2021-23556 | 6.4 MEDIUM | Exposed Dangerous Method or Function |
| CVE-2022-25296 | 6.3 MEDIUM | Prototype Pollution |
| CVE-2022-21221 | 5.9 MEDIUM | Directory Traversal |
| CVE-2021-46107 | Ligeo Archives 代码问题漏洞 | |
| CVE-2022-26501 | Veeam Backup&Replication 访问控制错误漏洞 | |
| CVE-2021-45040 | Spatie Laravel Media Library Pro 代码问题漏洞 | |
| CVE-2022-26503 | Veeam Agent for Windows 代码问题漏洞 | |
| CVE-2020-15591 | F*EX 代码注入漏洞 | |
| CVE-2021-44908 | Sails.js 注入漏洞 | |
| CVE-2022-26526 | Anaconda Anaconda3和Miniconda3 代码问题漏洞 | |
| CVE-2022-26504 | Veeam Backup&Replication 授权问题漏洞 | |
| CVE-2022-26500 | Veeam Backup&Replication 路径遍历漏洞 | |
| CVE-2022-24302 | Paramiko 竞争条件问题漏洞 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet