gradle-8
Chainguard
7.8
CVSS V3
Status
Justification
Impact
CVE is disputed. It relates to exposed passwords when using h2 via command-line. h2 is in use by Gradle as a library, and there is no reference of the CVE-related CLI argument being used in the codebase. Project maintainer's position: https://github.com/gradle/gradle/issues/24708#issuecomment-1508321833