CVE-2023-42445

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, resolving XML external entities is not disabled. Combined with an Out Of Band XXE attack (OOB-XXE), just parsing XML can lead to exfiltration of local text files to a remote server. Gradle parses XML files for several purposes. Most of the time, Gradle parses XML files it generated or were already present locally. Only Ivy XML descriptors and Maven POM files can be fetched from remote repositories and parsed by Gradle. In Gradle 7.6.3 and 8.4, resolving XML external entities has been disabled for all use cases to protect against this vulnerability. Gradle will now refuse to parse XML files that have XML external entities.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gradle:gradle:*:*:*:*:*:*:*:*
cpe:2.3:a:gradle:gradle:*:*:*:*:*:*:*:*

History

16 Feb 2024, 15:27

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20231110-0006/ - () https://security.netapp.com/advisory/ntap-20231110-0006/ - Third Party Advisory

10 Nov 2023, 18:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20231110-0006/ -

11 Oct 2023, 17:26

Type Values Removed Values Added
References (MISC) https://github.com/gradle/gradle/releases/tag/v8.4.0 - (MISC) https://github.com/gradle/gradle/releases/tag/v8.4.0 - Release Notes
References (MISC) https://github.com/gradle/gradle/releases/tag/v7.6.3 - (MISC) https://github.com/gradle/gradle/releases/tag/v7.6.3 - Release Notes
References (MISC) https://github.com/gradle/gradle/security/advisories/GHSA-mrff-q8qj-xvg8 - (MISC) https://github.com/gradle/gradle/security/advisories/GHSA-mrff-q8qj-xvg8 - Vendor Advisory
First Time Gradle gradle
Gradle
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:gradle:gradle:*:*:*:*:*:*:*:*

06 Oct 2023, 15:25

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-06 14:15

Updated : 2024-03-06 15:20


NVD link : CVE-2023-42445

Mitre link : CVE-2023-42445

CVE.ORG link : CVE-2023-42445


JSON object : View

Products Affected

gradle

  • gradle
CWE
CWE-611

Improper Restriction of XML External Entity Reference