Develocity Password Hash Exposure Vulnerability

Vulnerability

A vulnerability in Develocity (formerly Gradle Enterprise) versions prior to 2024.3.1 allows an attacker with network access to a Develocity server to retrieve the hashed password of the system user. While the hashing algorithm follows best practices for password storage and offers some resistance to brute-force attacks, the vulnerability's severity is heightened if the server is accessible to external or unauthorized users, and depends on the complexity of the system user's password.

Impact

Exploitation of this vulnerability could lead to the exposure of hashed passwords, which could potentially be subjected to cracking attempts, especially if the passwords are not complex.

Remediation

Users are advised to upgrade to Develocity versions 2024.1.9, 2024.2.7, or 2024.3.1 or later. After upgrading, it is recommended to change the system user's password to a long and complex one that follows best practices.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.