CVE-2020-15777 is a critical deserialization vulnerability affecting the Maven Extension plugin before version 1.6 for Gradle Enterprise. The extension's use of unrestricted deserialization of Java objects over an unbounded socket connection allows for remote code execution (RCE) and local privilege escalation (LPE) through malicious gadget chains. With a CVSS score of 7.8 (High), exploitation requires local access and low privileges, but no user interaction. Despite its high severity, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6CPE matchmatch criteria | cpe:2.3:a:gradle:maven:*:*:*:*:*:gradle:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.