CVE-2019-11403: Gradle Build Cache Node
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML page source of the settings page.
Affected products
- Gradle Build Cache Node: before 5.2 (fixed in 5.2)
- Gradle Enterprise: before 2018.5.2 (fixed in 2018.5.2)
Published 2019-04-22. Last modified 2026-06-17.