Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pprq-4488-wgqx

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Insecure transport protocol in Gradle

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

Пакеты

Наименование

org.gradle:gradle-core

maven
Затронутые версииВерсия исправления

>= 1.4, < 5.4.0

5.4.0

EPSS

Процентиль: 58%
0.0037
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 7 лет назад

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

CVSS3: 8.1
redhat
почти 7 лет назад

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

CVSS3: 5.9
nvd
почти 7 лет назад

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

CVSS3: 5.9
debian
почти 7 лет назад

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download ...

EPSS

Процентиль: 58%
0.0037
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319