Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensitive build/configuration details) via a crafted HTTP request with the X-Gradle-Enterprise-Ajax-Request header.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Gradle | Gradle | 2020.4 (including) | 2021.1.3 (excluding) |