Enterprise
Vendor:
First CVE: Apr 22, 2019 · Active for 7 years
23
Total CVEs
More Total CVEs than 96% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Enterprise over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
Jan 26, 2025
547 days ago
CVE Severity & Scoring
Enterprise23 CVEs
35%
43%
22%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.3%)
Network21 (91.3%)
Unknown0 (0.0%)
Physical1 (4.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low3 (13.0%)
High2 (8.7%)
None18 (78.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27919CRITICAL Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous a | Mar 25, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-41589CRITICAL In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node wit | Oct 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-11403CRITICAL In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page. | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11402CRITICAL In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. | Apr 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-15776HIGH An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the abil | Sep 18, 2020 | 8.8 | 28 | NO | NO |
CVE-2025-24858HIGH Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash | Jan 26, 2025 | 8.3 | 27 | NO | NO |
CVE-2023-49238CRITICAL In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system us | Jan 9, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-41575HIGH A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g | Oct 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-41574HIGH An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups from occurring, and send emails with arbitrary text content | Oct 7, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-41619HIGH An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration use | Oct 27, 2021 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Enterprise
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2018.5 | 1 | 5.5 | 0.3% | 0 | 0 |
| 2018.2 | 1 | 7.5 | 1.0% | 0 | 0 |