PT-2019-12162 · Gradle+1 · Gradle+1

·

CVE-2019-11065

·

Published

2019-04-09

·

Updated

2023-03-01

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gradle versions 1.4 through 5.3.1
Description The issue arises from Gradle using an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. This could allow dependency artifacts to be maliciously compromised by a Man-In-The-Middle (MITM) attack against the ajax.googleapis.com website.
Recommendations For Gradle versions 1.4 through 5.3.1, consider updating the plugin configurations to use secure HTTPS URLs for dependency downloads as a temporary workaround. Restrict access to the affected plugins to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11065
GHSA-PPRQ-4488-WGQX
USN-4858-1

Affected Products

Gradle
Ubuntu