A vulnerability was found in gradle. ObjectSocketWrapper.java allows remote attackers to execute arbitrary code via a crafted serialized object. References: https://philwantsfish.github.io/security/java-deserialization-github https://discuss.gradle.org/t/a-security-issue-about-gradle-rce/17726
Created gradle tracking bugs for this issue: Affects: fedora-24 [bug 1420347] Affects: epel-6 [bug 1420348]