Back to bug 2219505

Who When What Removed Added
TEJ RATHI 2023-07-04 05:25:13 UTC CC hhorak, jorton, mizdebsk
TEJ RATHI 2023-07-04 05:36:19 UTC Blocks 2219508
TEJ RATHI 2023-07-04 05:39:21 UTC Depends On 2219510
Red Hat Bugzilla 2023-07-07 08:32:15 UTC Assignee security-response-team nobody
Chess Hazlett 2023-08-08 21:29:27 UTC CC anstephe, avibelli, bgeorges, clement.escoffier, dandread, gsmet, hamadhan, jmartisk, lthon, max.andersen, peholase, pgallagh, probinso, rruss, rsvoboda, sbiarozk, sdouglas, tqvarnst
Chess Hazlett 2023-08-08 22:00:46 UTC Doc Text Gradle was found to permit directory traversal in its evaluation of repository paths. A local attacker could use this flaw to overwrite a file in the dependency cache with malicious code.
Chess Hazlett 2023-08-08 22:04:25 UTC Alias TRIAGE-CVE-2023-35946 CVE-2023-35946
Summary TRIAGE-CVE-2023-35946 gradle: Dependency cache path traversal CVE-2023-35946 gradle: Dependency cache path traversal
Paige Jung 2023-08-08 22:34:35 UTC Doc Text Gradle was found to permit directory traversal in its evaluation of repository paths. A local attacker could use this flaw to overwrite a file in the dependency cache with malicious code. A flaw was found in Gradle that permits directory traversal in its evaluation of repository paths. This issue could allow a local attacker to overwrite a file in the dependency cache with malicious code.

Back to bug 2219505