CVE-2019-11065

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
gradlegradle
1.4 ≤
𝑥
≤ 5.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gradle
bullseye
4.4.1-13
fixed
buster
no-dsa
stretch
no-dsa
jessie
no-dsa
bookworm
4.4.1-18
fixed
sid
4.4.1-20
fixed
trixie
4.4.1-20
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gradle
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
ignored
disco
ignored
cosmic
ignored
bionic
Fixed 4.4.1-5ubuntu2~18.04+esm1
released
xenial
needed
trusty
dne