CVE-2020-15772: Gradle Enterprise
Medium severity, CVSS 4.9. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities (XXE), allowing a remote attacker with administrative access to perform server side request forgery.
Affected products
- Gradle Enterprise: from 2018.5, up to and including 2020.2.4
Published 2020-09-18. Last modified 2026-06-17.