← Back to browse · API

CVE-2019-15052

Severity
CRITICAL
CVSS
9.8
EPSS
0.02925
Risk score
40.22
CISA KEV
No
PoC
No
Published
2019-08-14
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2019-6138, GHSA-XX6J-WQJ7-MRV3
Products
n/a:n/a n/a
Sources
euvd EUVD-2019-6138

Description

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

References