Vulnerability Details CVE-2020-15772
An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities (XXE), allowing a remote attacker with administrative access to perform server side request forgery.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.9%
CVSS Severity
CVSS v3 Score 4.9
CVSS v2 Score 4.0
Products affected by CVE-2020-15772
-
cpe:2.3:a:gradle:enterprise:2018.5
-
cpe:2.3:a:gradle:enterprise:2018.5.1
-
cpe:2.3:a:gradle:enterprise:2018.5.2
-
cpe:2.3:a:gradle:enterprise:2018.5.3
-
cpe:2.3:a:gradle:enterprise:2020.1
-
cpe:2.3:a:gradle:enterprise:2020.2
-
cpe:2.3:a:gradle:enterprise:2020.2.4