PT-2019-12162 · Gradle+1 · Gradle+1

Mikolaj Izdebski

·

Published

2019-04-09

·

Updated

2023-03-01

·

CVE-2019-11065

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gradle versions 1.4 through 5.3.1
Description The issue arises from Gradle using an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. This could allow dependency artifacts to be maliciously compromised by a Man-In-The-Middle (MITM) attack against the ajax.googleapis.com website.
Recommendations For Gradle versions 1.4 through 5.3.1, consider updating the plugin configurations to use secure HTTPS URLs for dependency downloads as a temporary workaround. Restrict access to the affected plugins to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2019-11065
GHSA-PPRQ-4488-WGQX
USN-4858-1

Affected Products

Gradle
Ubuntu