Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gradle | Gradle | 2020.4 (including) | 2021.1.3 (excluding) |