CVE-2019-15052: Gradle
Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.
Affected products
- Gradle Gradle: before 5.6 (fixed in 5.6)
Published 2019-08-14. Last modified 2026-06-17.