Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-42445

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.6%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2023-42445
  • Gradle » Gradle » Version: N/A
    cpe:2.3:a:gradle:gradle:-
  • Gradle » Gradle » Version: 0.1
    cpe:2.3:a:gradle:gradle:0.1
  • Gradle » Gradle » Version: 0.1.1
    cpe:2.3:a:gradle:gradle:0.1.1
  • Gradle » Gradle » Version: 0.1.2
    cpe:2.3:a:gradle:gradle:0.1.2
  • Gradle » Gradle » Version: 0.1.3
    cpe:2.3:a:gradle:gradle:0.1.3
  • Gradle » Gradle » Version: 0.1.4
    cpe:2.3:a:gradle:gradle:0.1.4
  • Gradle » Gradle » Version: 0.2
    cpe:2.3:a:gradle:gradle:0.2
  • Gradle » Gradle » Version: 0.3
    cpe:2.3:a:gradle:gradle:0.3
  • Gradle » Gradle » Version: 0.4
    cpe:2.3:a:gradle:gradle:0.4
  • Gradle » Gradle » Version: 0.5
    cpe:2.3:a:gradle:gradle:0.5
  • Gradle » Gradle » Version: 0.5.1
    cpe:2.3:a:gradle:gradle:0.5.1
  • Gradle » Gradle » Version: 0.5.2
    cpe:2.3:a:gradle:gradle:0.5.2
  • Gradle » Gradle » Version: 0.6
    cpe:2.3:a:gradle:gradle:0.6
  • Gradle » Gradle » Version: 0.6.1
    cpe:2.3:a:gradle:gradle:0.6.1
  • Gradle » Gradle » Version: 0.7
    cpe:2.3:a:gradle:gradle:0.7
  • Gradle » Gradle » Version: 0.8
    cpe:2.3:a:gradle:gradle:0.8
  • Gradle » Gradle » Version: 0.9
    cpe:2.3:a:gradle:gradle:0.9
  • Gradle » Gradle » Version: 0.9.1
    cpe:2.3:a:gradle:gradle:0.9.1
  • Gradle » Gradle » Version: 0.9.2
    cpe:2.3:a:gradle:gradle:0.9.2
  • Gradle » Gradle » Version: 1.0
    cpe:2.3:a:gradle:gradle:1.0
  • Gradle » Gradle » Version: 1.1
    cpe:2.3:a:gradle:gradle:1.1
  • Gradle » Gradle » Version: 1.10
    cpe:2.3:a:gradle:gradle:1.10
  • Gradle » Gradle » Version: 1.11
    cpe:2.3:a:gradle:gradle:1.11
  • Gradle » Gradle » Version: 1.12
    cpe:2.3:a:gradle:gradle:1.12
  • Gradle » Gradle » Version: 1.2
    cpe:2.3:a:gradle:gradle:1.2
  • Gradle » Gradle » Version: 1.3
    cpe:2.3:a:gradle:gradle:1.3
  • Gradle » Gradle » Version: 1.3.1
    cpe:2.3:a:gradle:gradle:1.3.1
  • Gradle » Gradle » Version: 1.4
    cpe:2.3:a:gradle:gradle:1.4
  • Gradle » Gradle » Version: 1.5
    cpe:2.3:a:gradle:gradle:1.5
  • Gradle » Gradle » Version: 1.6
    cpe:2.3:a:gradle:gradle:1.6
  • Gradle » Gradle » Version: 1.7
    cpe:2.3:a:gradle:gradle:1.7
  • Gradle » Gradle » Version: 1.8
    cpe:2.3:a:gradle:gradle:1.8
  • Gradle » Gradle » Version: 1.9
    cpe:2.3:a:gradle:gradle:1.9
  • Gradle » Gradle » Version: 2.0
    cpe:2.3:a:gradle:gradle:2.0
  • Gradle » Gradle » Version: 2.1
    cpe:2.3:a:gradle:gradle:2.1
  • Gradle » Gradle » Version: 2.10
    cpe:2.3:a:gradle:gradle:2.10
  • Gradle » Gradle » Version: 2.11
    cpe:2.3:a:gradle:gradle:2.11
  • Gradle » Gradle » Version: 2.12
    cpe:2.3:a:gradle:gradle:2.12
  • Gradle » Gradle » Version: 2.13
    cpe:2.3:a:gradle:gradle:2.13
  • Gradle » Gradle » Version: 2.14
    cpe:2.3:a:gradle:gradle:2.14
  • Gradle » Gradle » Version: 2.14.1
    cpe:2.3:a:gradle:gradle:2.14.1
  • Gradle » Gradle » Version: 2.2
    cpe:2.3:a:gradle:gradle:2.2
  • Gradle » Gradle » Version: 2.2.1
    cpe:2.3:a:gradle:gradle:2.2.1
  • Gradle » Gradle » Version: 2.3
    cpe:2.3:a:gradle:gradle:2.3
  • Gradle » Gradle » Version: 2.4
    cpe:2.3:a:gradle:gradle:2.4
  • Gradle » Gradle » Version: 2.5
    cpe:2.3:a:gradle:gradle:2.5
  • Gradle » Gradle » Version: 2.6
    cpe:2.3:a:gradle:gradle:2.6
  • Gradle » Gradle » Version: 2.7
    cpe:2.3:a:gradle:gradle:2.7
  • Gradle » Gradle » Version: 2.8
    cpe:2.3:a:gradle:gradle:2.8
  • Gradle » Gradle » Version: 2.9
    cpe:2.3:a:gradle:gradle:2.9
  • Gradle » Gradle » Version: 3.0.0
    cpe:2.3:a:gradle:gradle:3.0.0
  • Gradle » Gradle » Version: 3.1.0
    cpe:2.3:a:gradle:gradle:3.1.0
  • Gradle » Gradle » Version: 3.2.0
    cpe:2.3:a:gradle:gradle:3.2.0
  • Gradle » Gradle » Version: 3.2.1
    cpe:2.3:a:gradle:gradle:3.2.1
  • Gradle » Gradle » Version: 3.3.0
    cpe:2.3:a:gradle:gradle:3.3.0
  • Gradle » Gradle » Version: 3.4.0
    cpe:2.3:a:gradle:gradle:3.4.0
  • Gradle » Gradle » Version: 3.4.1
    cpe:2.3:a:gradle:gradle:3.4.1
  • Gradle » Gradle » Version: 3.5.0
    cpe:2.3:a:gradle:gradle:3.5.0
  • Gradle » Gradle » Version: 3.5.1
    cpe:2.3:a:gradle:gradle:3.5.1
  • Gradle » Gradle » Version: 4.0.0
    cpe:2.3:a:gradle:gradle:4.0.0
  • Gradle » Gradle » Version: 4.0.1
    cpe:2.3:a:gradle:gradle:4.0.1
  • Gradle » Gradle » Version: 4.0.2
    cpe:2.3:a:gradle:gradle:4.0.2
  • Gradle » Gradle » Version: 4.1.0
    cpe:2.3:a:gradle:gradle:4.1.0
  • Gradle » Gradle » Version: 4.10.0
    cpe:2.3:a:gradle:gradle:4.10.0
  • Gradle » Gradle » Version: 4.10.1
    cpe:2.3:a:gradle:gradle:4.10.1
  • Gradle » Gradle » Version: 4.10.2
    cpe:2.3:a:gradle:gradle:4.10.2
  • Gradle » Gradle » Version: 4.10.3
    cpe:2.3:a:gradle:gradle:4.10.3
  • Gradle » Gradle » Version: 4.2.0
    cpe:2.3:a:gradle:gradle:4.2.0
  • Gradle » Gradle » Version: 4.2.1
    cpe:2.3:a:gradle:gradle:4.2.1
  • Gradle » Gradle » Version: 4.3.0
    cpe:2.3:a:gradle:gradle:4.3.0
  • Gradle » Gradle » Version: 4.3.1
    cpe:2.3:a:gradle:gradle:4.3.1
  • Gradle » Gradle » Version: 4.4.0
    cpe:2.3:a:gradle:gradle:4.4.0
  • Gradle » Gradle » Version: 4.4.1
    cpe:2.3:a:gradle:gradle:4.4.1
  • Gradle » Gradle » Version: 4.5.0
    cpe:2.3:a:gradle:gradle:4.5.0
  • Gradle » Gradle » Version: 4.5.1
    cpe:2.3:a:gradle:gradle:4.5.1
  • Gradle » Gradle » Version: 4.6.0
    cpe:2.3:a:gradle:gradle:4.6.0
  • Gradle » Gradle » Version: 4.7.0
    cpe:2.3:a:gradle:gradle:4.7.0
  • Gradle » Gradle » Version: 4.8.0
    cpe:2.3:a:gradle:gradle:4.8.0
  • Gradle » Gradle » Version: 4.8.1
    cpe:2.3:a:gradle:gradle:4.8.1
  • Gradle » Gradle » Version: 4.9.0
    cpe:2.3:a:gradle:gradle:4.9.0
  • Gradle » Gradle » Version: 5.0.0
    cpe:2.3:a:gradle:gradle:5.0.0
  • Gradle » Gradle » Version: 5.1.0
    cpe:2.3:a:gradle:gradle:5.1.0
  • Gradle » Gradle » Version: 5.1.1
    cpe:2.3:a:gradle:gradle:5.1.1
  • Gradle » Gradle » Version: 5.2.0
    cpe:2.3:a:gradle:gradle:5.2.0
  • Gradle » Gradle » Version: 5.2.1
    cpe:2.3:a:gradle:gradle:5.2.1
  • Gradle » Gradle » Version: 5.3.0
    cpe:2.3:a:gradle:gradle:5.3.0
  • Gradle » Gradle » Version: 5.4.0
    cpe:2.3:a:gradle:gradle:5.4.0
  • Gradle » Gradle » Version: 5.4.1
    cpe:2.3:a:gradle:gradle:5.4.1
  • Gradle » Gradle » Version: 5.5.0
    cpe:2.3:a:gradle:gradle:5.5.0
  • Gradle » Gradle » Version: 5.5.1
    cpe:2.3:a:gradle:gradle:5.5.1
  • Gradle » Gradle » Version: 5.6
    cpe:2.3:a:gradle:gradle:5.6
  • Gradle » Gradle » Version: 5.6.0
    cpe:2.3:a:gradle:gradle:5.6.0
  • Gradle » Gradle » Version: 5.6.1
    cpe:2.3:a:gradle:gradle:5.6.1
  • Gradle » Gradle » Version: 5.6.2
    cpe:2.3:a:gradle:gradle:5.6.2
  • Gradle » Gradle » Version: 5.6.3
    cpe:2.3:a:gradle:gradle:5.6.3
  • Gradle » Gradle » Version: 5.6.4
    cpe:2.3:a:gradle:gradle:5.6.4
  • Gradle » Gradle » Version: 6.0
    cpe:2.3:a:gradle:gradle:6.0
  • Gradle » Gradle » Version: 6.0.0
    cpe:2.3:a:gradle:gradle:6.0.0
  • Gradle » Gradle » Version: 6.0.1
    cpe:2.3:a:gradle:gradle:6.0.1
  • Gradle » Gradle » Version: 6.1.0
    cpe:2.3:a:gradle:gradle:6.1.0
  • Gradle » Gradle » Version: 6.1.1
    cpe:2.3:a:gradle:gradle:6.1.1
  • Gradle » Gradle » Version: 6.2.0
    cpe:2.3:a:gradle:gradle:6.2.0
  • Gradle » Gradle » Version: 6.2.1
    cpe:2.3:a:gradle:gradle:6.2.1
  • Gradle » Gradle » Version: 6.2.2
    cpe:2.3:a:gradle:gradle:6.2.2
  • Gradle » Gradle » Version: 6.3.0
    cpe:2.3:a:gradle:gradle:6.3.0
  • Gradle » Gradle » Version: 6.4.0
    cpe:2.3:a:gradle:gradle:6.4.0
  • Gradle » Gradle » Version: 6.4.1
    cpe:2.3:a:gradle:gradle:6.4.1
  • Gradle » Gradle » Version: 6.5.0
    cpe:2.3:a:gradle:gradle:6.5.0
  • Gradle » Gradle » Version: 6.5.1
    cpe:2.3:a:gradle:gradle:6.5.1
  • Gradle » Gradle » Version: 6.6.0
    cpe:2.3:a:gradle:gradle:6.6.0
  • Gradle » Gradle » Version: 6.6.1
    cpe:2.3:a:gradle:gradle:6.6.1
  • Gradle » Gradle » Version: 6.7.0
    cpe:2.3:a:gradle:gradle:6.7.0
  • Gradle » Gradle » Version: 6.7.1
    cpe:2.3:a:gradle:gradle:6.7.1
  • Gradle » Gradle » Version: 6.8.0
    cpe:2.3:a:gradle:gradle:6.8.0
  • Gradle » Gradle » Version: 6.8.1
    cpe:2.3:a:gradle:gradle:6.8.1
  • Gradle » Gradle » Version: 6.8.2
    cpe:2.3:a:gradle:gradle:6.8.2
  • Gradle » Gradle » Version: 6.8.3
    cpe:2.3:a:gradle:gradle:6.8.3
  • Gradle » Gradle » Version: 6.9.0
    cpe:2.3:a:gradle:gradle:6.9.0
  • Gradle » Gradle » Version: 7.0.0
    cpe:2.3:a:gradle:gradle:7.0.0
  • Gradle » Gradle » Version: 7.0.1
    cpe:2.3:a:gradle:gradle:7.0.1
  • Gradle » Gradle » Version: 7.0.2
    cpe:2.3:a:gradle:gradle:7.0.2
  • Gradle » Gradle » Version: 7.1.0
    cpe:2.3:a:gradle:gradle:7.1.0
  • Gradle » Gradle » Version: 7.1.1
    cpe:2.3:a:gradle:gradle:7.1.1
  • Gradle » Gradle » Version: 7.2
    cpe:2.3:a:gradle:gradle:7.2
  • Gradle » Gradle » Version: 7.2.0
    cpe:2.3:a:gradle:gradle:7.2.0
  • Gradle » Gradle » Version: 7.3.0
    cpe:2.3:a:gradle:gradle:7.3.0
  • Gradle » Gradle » Version: 7.3.1
    cpe:2.3:a:gradle:gradle:7.3.1
  • Gradle » Gradle » Version: 7.3.2
    cpe:2.3:a:gradle:gradle:7.3.2
  • Gradle » Gradle » Version: 7.3.3
    cpe:2.3:a:gradle:gradle:7.3.3
  • Gradle » Gradle » Version: 7.4.0
    cpe:2.3:a:gradle:gradle:7.4.0
  • Gradle » Gradle » Version: 7.4.1
    cpe:2.3:a:gradle:gradle:7.4.1
  • Gradle » Gradle » Version: 7.4.2
    cpe:2.3:a:gradle:gradle:7.4.2
  • Gradle » Gradle » Version: 7.5.0
    cpe:2.3:a:gradle:gradle:7.5.0
  • Gradle » Gradle » Version: 7.5.1
    cpe:2.3:a:gradle:gradle:7.5.1
  • Gradle » Gradle » Version: 7.6.0
    cpe:2.3:a:gradle:gradle:7.6.0
  • Gradle » Gradle » Version: 7.6.1
    cpe:2.3:a:gradle:gradle:7.6.1
  • Gradle » Gradle » Version: 7.6.2
    cpe:2.3:a:gradle:gradle:7.6.2
  • Gradle » Gradle » Version: 8.0.0
    cpe:2.3:a:gradle:gradle:8.0.0
  • Gradle » Gradle » Version: 8.0.1
    cpe:2.3:a:gradle:gradle:8.0.1
  • Gradle » Gradle » Version: 8.0.2
    cpe:2.3:a:gradle:gradle:8.0.2
  • Gradle » Gradle » Version: 8.1.0
    cpe:2.3:a:gradle:gradle:8.1.0
  • Gradle » Gradle » Version: 8.1.1
    cpe:2.3:a:gradle:gradle:8.1.1
  • Gradle » Gradle » Version: 8.2.0
    cpe:2.3:a:gradle:gradle:8.2.0
  • Gradle » Gradle » Version: 8.2.1
    cpe:2.3:a:gradle:gradle:8.2.1
  • Gradle » Gradle » Version: 8.3.0
    cpe:2.3:a:gradle:gradle:8.3.0


Contact Us

Shodan ® - All rights reserved