Loading
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an attacker logs in before the legitimate administrator logs in.
Use CWE-521, Gradle vendor hub and Enterprise product page to widen CVE-2023-49238 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-27919, CVE-2021-41589 and CVE-2020-15776 for nearby disclosures in the same product family.