Lucene search

K
osvGoogleOSV:SUSE-SU-2024:3163-1
HistorySep 06, 2024 - 10:18 a.m.

Security update for gradle

2024-09-0610:18:54
Google
osv.dev
2
gradle
security update
cve-2023-35946
dependency issue
cache
unintended location
bsc#1212930

CVSS3

6.9

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L

AI Score

6.7

Confidence

Low

This update for gradle fixes the following issues:

  • CVE-2023-35946: Fixed a dependency issue leading the cache to write files into an unintended location. (bsc#1212930)

CVSS3

6.9

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L

AI Score

6.7

Confidence

Low