Vulnerability Name: | CVE-2021-41590 (CCN-212301) | ||||||||||||
Assigned: | 2021-09-24 | ||||||||||||
Published: | 2021-09-24 | ||||||||||||
Updated: | 2022-07-12 | ||||||||||||
Summary: | In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-41590 Source: XF Type: UNKNOWN gradle-cve202141590-info-disc(212301) Source: MISC Type: Vendor Advisory https://security.gradle.com Source: CCN Type: Gradle Security Advisory 2021-07 Potential probing of server side network environment via SMTP configuration test Source: MISC Type: Vendor Advisory https://security.gradle.com/advisory/2021-07 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |