In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encryption and signing keys.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:gradle:gradle:*:*:*:*:enterprise:*:*:*"
]
}