← Vulnerability feed

Vulnerability record · CVE-2019-15052 · published 14 August 2019

CVE-2019-15052: Gradle insufficiently protected credentials vulnerability

Gradle · Gradle

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

9.8 CVSS 3.1 Critical EPSS 2.8% · top 13.8% CWE-522 · Insufficiently protected credentials
9.8CVSS 3.1 base score, v2 5.0
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/gradle/gradle/issues/10278 ExploitIssue TrackingThird Party Advisory
https://github.com/gradle/gradle/pull/10176 Issue TrackingPatchThird Party Advisory
https://github.com/gradle/gradle/security/advisories/GHSA-4cwg-f7qc-6r95 ExploitThird Party Advisory
https://github.com/gradle/gradle/issues/10278 ExploitIssue TrackingThird Party Advisory
https://github.com/gradle/gradle/pull/10176 Issue TrackingPatchThird Party Advisory
https://github.com/gradle/gradle/security/advisories/GHSA-4cwg-f7qc-6r95 ExploitThird Party Advisory

Track CVE-2019-15052 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26053Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…EPSS 0.99%9.8CVE-2016-6199Gradle deserialization of untrusted data vulnerabilityObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.EPSS 4.7%8.6CVE-2026-22816Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.17%8.6CVE-2026-22865Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.16%8.1CVE-2023-35947Gradle path traversal vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…EPSS 0.53%8.1CVE-2021-41588Gradle deserialization of untrusted data vulnerabilityIn Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…EPSS 0.80%7.8CVE-2021-29428Gradle vulnerabilityIn Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …EPSS 0.53%7.5CVE-2022-23630Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-15052), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.