{"id":"CVE-2020-15768","details":"An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS vulnerability. This potentially allows an attacker to impersonate another user. Gradle Enterprise affected application request paths:/info/headers, /cache-info/headers, /admin-info/headers, /distribution-broker-info/headers. Gradle Enterprise Build Cache Node affected application request paths:/cache-node-info/headers.","modified":"2026-04-10T04:23:05.688806Z","published":"2020-09-18T14:15:12.137Z","references":[{"type":"ADVISORY","url":"https://security.gradle.com/advisory/CVE-2020-15768"},{"type":"ADVISORY","url":"https://github.com/gradle/gradle/security/advisories"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gradle/gradle","events":[{"introduced":"c69571460f7035fa40827f72b2b5cfeb362afd20"},{"last_affected":"d9d6bbce03b3d88c67ef5a0ff31f7ae5e332d6bf"}],"database_specific":{"versions":[{"introduced":"1.0"},{"last_affected":"9.2"}]}}],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"2017.3"},{"last_affected":"2020.2.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15768.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}