← Vulnerability feed

Vulnerability record · CVE-2022-23630 · published 10 February 2022

CVE-2022-23630: Gradle inclusion from untrusted sphere vulnerability

Gradle · Gradle

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency verification is disabled on one or more configurations and those configurations have common dependencies with other configurations that have dependency verification enabled. If the configuration that has dependency verification disabled is resolved first, Gradle does not verify the common dependencies for the configuration that has dependency verification enabled. Gradle 7.4 fixes that issue by validating artifacts at least once if they are present in a resolved configuration that has dependency verification active. For users who cannot update either do not use `ResolutionStrategy.disableDependencyVerification()` and do not use plugins that use that method to disable dependency verification for a single configuration or make sure resolution of configuration that disable that feature do not happen in builds that resolve configuration where the feature is enabled.

7.5 CVSS 3.1 High EPSS 1.3% · top 30.3% CWE-829 · Inclusion from untrusted sphere
7.5CVSS 3.1 base score, v2 6.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This occurs when dependency verification is disabled on one or more configurations and those configurations have common dependencies with other configurations that have dependency verification enabled. If the configuration that has dependency verification disabled is resolved first, Gradle does not verify the common dependencies for the configuration that has dependency verification enabled. Gradle 7.4 fixes that issue by validating artifacts at least once if they are present in a resolved configuration that has dependency verification active. For users who cannot update either do not use `ResolutionStrategy.disableDependencyVerification()` and do not use plugins that use that method to disable dependency verification for a single configuration or make sure resolution of configuration that disable that feature do not happen in builds that resolve configuration where the feature is enabled.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-23630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-26053Gradle inclusion from untrusted sphere vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. This is a collision attack on long IDs (64bits) f…EPSS 0.99%9.8CVE-2019-15052Gradle insufficiently protected credentials vulnerabilityThe HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirec…EPSS 2.8%9.8CVE-2016-6199Gradle deserialization of untrusted data vulnerabilityObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.EPSS 4.7%8.6CVE-2026-22816Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.17%8.6CVE-2026-22865Gradle download of code without integrity check vulnerabilityGradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions befor…EPSS 0.16%8.1CVE-2023-35947Gradle path traversal vulnerabilityGradle is a build tool with a focus on build automation and support for multi-language development. In affected versions when unpacking Tar archives,…EPSS 0.53%8.1CVE-2021-41588Gradle deserialization of untrusted data vulnerabilityIn Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…EPSS 0.80%7.8CVE-2021-29428Gradle vulnerabilityIn Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to …EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2022-23630), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.