CVE-2021-26719
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
Se detectó un problema de salto de directorio en Gradle gradle-enterprise-test-distribution-agent versiones anteriores a 1.3.2, test-distribution-gradle-plugin versiones anteriores a 1.3.2 y gradle-enterprise-maven-extension versiones anteriores a 1.8.2. Un actor malicioso (con determinadas credenciales) puede llevar a cabo un paso de registro de modo que los archivos TAR diseñados conlleven a una extracción de archivos en ubicaciones arbitrarias del sistema de archivos
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-05 CVE Reserved
- 2021-02-09 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gradle.com/advisory/CVE-2021-26719 | 2021-02-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gradle Search vendor "Gradle" | Enterprise Test Distribution Agent Search vendor "Gradle" for product "Enterprise Test Distribution Agent" | < 1.3.2 Search vendor "Gradle" for product "Enterprise Test Distribution Agent" and version " < 1.3.2" | - |
Affected
| ||||||
Gradle Search vendor "Gradle" | Maven Search vendor "Gradle" for product "Maven" | >= 1.8 <= 1.8.1 Search vendor "Gradle" for product "Maven" and version " >= 1.8 <= 1.8.1" | gradle |
Affected
| ||||||
Gradle Search vendor "Gradle" | Test Distribution Search vendor "Gradle" for product "Test Distribution" | < 1.3.2 Search vendor "Gradle" for product "Test Distribution" and version " < 1.3.2" | gradle |
Affected
|