Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS vulnerability. This potentially allows an attacker to impersonate another user.
Gradle Enterprise affected application request paths:
- /info/headers
- /cache-info/headers
- /admin-info/headers
- /distribution-broker-info/headers
Gradle Enterprise Build Cache Node affected application request paths:
- /cache-node-info/headers