Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhr2-f668-ff2w

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью

Описание

Use of a weak cryptographic algorithm in Gradle

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

Пакеты

Наименование

org.gradle:gradle-core

maven
Затронутые версииВерсия исправления

< 6.0

6.0

EPSS

Процентиль: 37%
0.00162
Низкий

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

CVSS3: 5.9
redhat
больше 6 лет назад

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

CVSS3: 5.9
nvd
больше 6 лет назад

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

CVSS3: 5.9
debian
больше 6 лет назад

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algori ...

EPSS

Процентиль: 37%
0.00162
Низкий

Дефекты

CWE-327