CVE-2023-49238
09.01.2024, 02:15
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.Enginsight
Vendor | Product | Version |
---|---|---|
gradle | enterprise | 𝑥 < 2023.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration