A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-13507 A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T20:33:40.821Z

Reserved: 2021-02-05T00:00:00

Link: CVE-2021-26719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-09T14:15:17.577

Modified: 2024-11-21T05:56:44.550

Link: CVE-2021-26719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.