CVE-2023-42445
Possible local file exfiltration by XML External entity injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.
Gradle es una herramienta de compilación centrada en la automatización de la build y soporte para el desarrollo en varios idiomas. En algunos casos, cuando Gradle analiza archivos XML, la resolución de entidades externas XML no está deshabilitada. Combinado con un ataque XXE fuera de banda (OOB-XXE), el simple hecho de analizar XML puede provocar la filtración de archivos de texto locales a un servidor remoto. Gradle analiza archivos XML para varios propósitos. La mayoría de las veces, Gradle analiza los archivos XML que generó o que ya estaban presentes localmente. Gradle solo puede recuperar los descriptores XML de Ivy y los archivos POM de Maven de repositorios remotos y analizarlos. En Gradle 7.6.3 y 8.4, la resolución de entidades externas XML se ha deshabilitado para todos los casos de uso para proteger contra esta vulnerabilidad. Gradle ahora se negará a analizar archivos XML que tengan entidades externas XML.
A flaw was found in Gradle. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), parsing XML can lead to the exfiltration of local text files to a remote server. In most cases, Gradle parses XML files it generated, or that were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-08 CVE Reserved
- 2023-10-06 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/gradle/gradle/releases/tag/v7.6.3 | Release Notes | |
https://github.com/gradle/gradle/releases/tag/v8.4.0 | Release Notes | |
https://security.netapp.com/advisory/ntap-20231110-0006 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/gradle/gradle/security/advisories/GHSA-mrff-q8qj-xvg8 | 2024-03-06 | |
https://access.redhat.com/security/cve/CVE-2023-42445 | 2023-12-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2242538 | 2023-12-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gradle Search vendor "Gradle" | Gradle Search vendor "Gradle" for product "Gradle" | < 7.6.3 Search vendor "Gradle" for product "Gradle" and version " < 7.6.3" | - |
Affected
| ||||||
Gradle Search vendor "Gradle" | Gradle Search vendor "Gradle" for product "Gradle" | >= 8.0.0 < 8.4.0 Search vendor "Gradle" for product "Gradle" and version " >= 8.0.0 < 8.4.0" | - |
Affected
|