Vulnerability CVE-2023-49238


Published: 2024-01-09

Description:
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.

 References:
https://security.gradle.com
https://security.gradle.com/advisory/2023-01

Copyright 2026, cxsecurity.com

 

Back to Top