cbcvebase.
CVE-2019-11065
published 2019-04-10

CVE-2019-11065: Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.37%
69.1th percentile
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiangradle< gradle 4.4.1-10 (bookworm)gradle 4.4.1-10 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gradlegradle>= 0 < 4.4.1-104.4.1-10
gradlegradle>= 0 < 4.4.1-104.4.1-10
gradlegradle>= 0 < 4.4.1-104.4.1-10
gradlegradle>= 0 < 4.4.1-104.4.1-10
gradlegradle>= 0 < 4.4.1-5ubuntu2~18.04+esm14.4.1-5ubuntu2~18.04+esm1
gradlegradle1.4 – 5.3.1

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.