Gradle Technologies is now Develocity — read the announcement

← All advisories

Potential remote code execution via application startup configuration

Affected product(s)
  • Gradle Enterprise 2020.4 - 2021.1.2
Severity
High
Published
May 31, 2021
Related CVE ID(s)

Description

The installation configuration user interface available to administrators allows specifying arbitrary Java Virtual Machine startup options. Some startup options, such as -XX:OnOutOfMemoryError, allow specifying a command to be run on the host. This can be abused to run arbitrary commands on the host, should an attacker gain administrative access to the application.

As of Gradle Enterprise 2021.1.2, such options are ignored.

Mitigation

Upgrade to Gradle Enterprise 2021.1.2 or later.

Credit

Marat Aytuganov <[email protected]>

© 2026 Gradle, Inc. Gradle®, Develocity®, Build Scan®, and the Gradlephant logo are registered trademarks of Gradle, Inc.

Get an AI summary of Develocity: