Prior to Gradle Enterprise 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated entries that execute malicious code as part of a build.
As of Gradle Enterprise 2021.4.2 the built-in build cache is inaccessible-by-default, requiring explicit configuration of its access control settings before it can be used.
Remote build cache nodes are unaffected as they are inaccessible-by-default.