CVE-2019-11065Cleartext Transmission of Sensitive Info in Gradle

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 42.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 13

Description

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

debiandebian/gradle< gradle 4.4.1-10 (bookworm)
Debiangradle/gradle< 4.4.1-10+3
Ubuntugradle/gradle< 4.4.1-5ubuntu2~18.04+esm1
NVDgradle/gradle1.45.3.1

Also affects: Fedora 28, 29, 30

Patches

🔴Vulnerability Details

4
GHSA
Insecure transport protocol in Gradle2022-05-13
OSV
Insecure transport protocol in Gradle2022-05-13
OSV
gradle vulnerabilities2021-03-15
OSV
CVE-2019-11065: Gradle versions from 12019-04-10

📋Vendor Advisories

3
Ubuntu
Gradle vulnerabilities2021-03-15
Red Hat
gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously compromised artifacts.2019-04-09
Debian
CVE-2019-11065: gradle - Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependenc...2019

💬Community

4
Bugzilla
CVE-2019-11065 gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously compromised artifacts. [fedora-28]2019-04-10
Bugzilla
CVE-2019-11065 gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously compromised artifacts.2019-04-10
Bugzilla
CVE-2019-11065 gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously compromised artifacts. [fedora-29]2019-04-10
Bugzilla
CVE-2019-11065 gradle: Insecure HTTP URL used to download dependencies leading to possibly maliciously compromised artifacts. [epel-6]2019-04-10