Loading
An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the API.
Use CWE-346, Gradle vendor hub and Enterprise product page to widen CVE-2020-15773 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-49238, CVE-2022-27919 and CVE-2021-41589 for nearby disclosures in the same product family.