Develocity Security Advisories
The following is a list of security advisories relating to Develocity and its associated components. Gradle Build Tool security advisories can be found on GitHub.
2025
| Published | Severity | Summary |
|---|---|---|
| Jul 21, 2025 | High | CCUD plugins information exposure |
| Jan 22, 2025 | High | Password hash information exposure |
2024
| Published | Severity | Summary |
|---|---|---|
| Oct 1, 2024 | Moderate | Project-Level Access Control may be disabled upon upgrade |
| Oct 1, 2024 | Low | Credential leak of AWS credentials via local information exposure |
| May 2, 2024 | Moderate | Cross-Site Request Forgery on Develocity API calls |
2023
| Published | Severity | Summary |
|---|---|---|
| Dec 4, 2023 | Moderate | Non-unique initial system user password may allow unauthorized access to new installation |
2022
2021
2020
| Published | Severity | Summary |
|---|---|---|
| Sep 18, 2020 | High | Build scan Export API is susceptible to cross-origin requests |
| Sep 15, 2020 | High | CSRF prevention token is overridable by user code |
| Sep 15, 2020 | Moderate | Build project names and build volumes are accessible without authentication |
| Sep 15, 2020 | Moderate | Login sessions are not terminated on browser closure |
| Sep 15, 2020 | Moderate | SAML IDP metadata XML upload is vulnerable to server-side request forgery via XXE injection |
| Sep 15, 2020 | Moderate | Request cookies containing CSRF prevention token are not same-site restricted |
| Sep 15, 2020 | Moderate | Local user login is susceptible to brute force password guessing |
| Sep 15, 2020 | Critical | Test distribution usage search form allows XSS |
| Sep 15, 2020 | Critical | Potential disclosure of session cookies via header reflection |
| Sep 15, 2020 | Moderate | CSRF prevention cookie is susceptible to capture by MITM on HTTP redirect |
| Jul 15, 2020 | Critical | Potential local privilege escalation during build due to unrestricted input deserialization |
2019
| Published | Severity | Summary |
|---|---|---|
| Apr 22, 2019 | High | Build cache credentials are reflected in administration screens |
| Apr 22, 2019 | High | Build cache credentials are stored unencrypted at rest |