Gradle Technologies is now Develocity — read the announcement

← All advisories

Build cache credentials are stored unencrypted at rest

Affected product(s)
  • Gradle Enterprise < 2018.5.3
  • Gradle Enterprise Build Cache Node < 6.0
Severity
High
Published
April 22, 2019
Related CVE ID(s)

Description

Build cache user credentials are stored unencrypted at the Gradle Enterprise server, and build cache nodes. An attacker gaining access to the server can obtain the passwords used to access the cache via the HTTP interface.

Mitigation

Upgrade to Gradle Enterprise 2018.5.3 and/or Gradle Enterprise Build Cache Node 6.0.

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: