SCA: security update for com.gradle:gradle-enterprise-maven-extension (GHSA-vp55-fhxx-vcx8)

high Tenable Cloud Security Plugin ID 434222

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses
a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list,
thus allowing an attacker to achieve code execution via a malicious deserialization gadget chain. The
socket is not bound exclusively to localhost. The port this socket is assigned to is randomly selected and
is not intentionally exposed to the public (either by design or documentation). This could potentially be
used to achieve remote code execution and local privilege escalation. (CVE-2020-15777)

See Also

https://github.com/advisories/GHSA-vp55-fhxx-vcx8

Plugin Details

Severity: High

ID: 434222

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-15777

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/24/2022

Vulnerability Publication Date: 8/25/2020

Reference Information

CVE: CVE-2020-15777

cwe: CWE-502