CVE-2019-11065

EUVD-2022-4803
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
gradlegradle
1.4 ≤
𝑥
≤ 5.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gradle
bookworm
4.4.1-18
fixed
bullseye
4.4.1-13
fixed
buster
no-dsa
jessie
no-dsa
sid
4.4.1-20
fixed
stretch
no-dsa
trixie
4.4.1-20
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gradle
bionic
Fixed 4.4.1-5ubuntu2~18.04+esm1
released
cosmic
ignored
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
needed