CVE-2024-46881
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-46881 is a vulnerability affecting Develocity (formerly Gradle Enterprise) versions before 2024.1.8. The issue involves incorrect access control, where project-level access configuration in Enterprise Config schema version 8 is not carried over during certain upgrades. This results in all project settings being reset to their defaults, effectively disabling project access control and exposing previously restricted project information. This occurs during upgrades from Develocity 2023.3.X, 2023.3.X to 2024.1.X (up to and including 2024.1.7), and 2023.4.X to 2024.1.X (up to and including 2024.1.7). Administrator access is required to trigger the upgrade, and the flaw does not allow external attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.