The HTTP client in the Build tool in Gradle before 5.6...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 10, 2023
Description
Published by the National Vulnerability Database
Aug 14, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 10, 2023
The HTTP client in the Build tool in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.
References