Loading
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.
Use CWE-522, Gradle vendor hub and Gradle product page to widen CVE-2019-15052 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22865, CVE-2026-22816 and CVE-2021-41588 for nearby disclosures in the same product family.