Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31156

Опубликовано: 14 июл. 2022
Источник: nvd
CVSS3: 6.6
CVSS3: 4.4
EPSS Низкий

Описание

Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This can occur in two ways. When signature verification is disabled but the verification metadata contains entries for dependencies that only have a gpg element but no checksum element. When signature verification is enabled, the verification metadata contains entries for dependencies with a gpg element but there is no signature file on the remote repository. In both cases, the verification will accept the dependency, skipping signature verification and not complaining that the dependency has no checksum entry. For builds that are vulnerable, there are two risks. Gradle could downlo

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gradle:gradle:*:*:*:*:*:*:*:*
Версия от 6.2.0 (включая) до 7.5.0 (исключая)

EPSS

Процентиль: 41%
0.00193
Низкий

6.6 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-829
CWE-347

Связанные уязвимости

CVSS3: 6.6
ubuntu
больше 3 лет назад

Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This can occur in two ways. When signature verification is disabled but the verification metadata contains entries for dependencies that only have a `gpg` element but no `checksum` element. When signature verification is enabled, the verification metadata contains entries for dependencies with a `gpg` element but there is no signature file on the remote repository. In both cases, the verification will accept the dependency, skipping signature verification and not complaining that the dependency has no checksum entry. For builds that are vulnerable, there are two risks. Gradle could dow...

CVSS3: 4.4
redhat
больше 3 лет назад

Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their checksum or cryptographic signatures. In versions 6.2 through 7.4.2, there are some cases in which Gradle may skip that verification and accept a dependency that would otherwise fail the build as an untrusted external artifact. This can occur in two ways. When signature verification is disabled but the verification metadata contains entries for dependencies that only have a `gpg` element but no `checksum` element. When signature verification is enabled, the verification metadata contains entries for dependencies with a `gpg` element but there is no signature file on the remote repository. In both cases, the verification will accept the dependency, skipping signature verification and not complaining that the dependency has no checksum entry. For builds that are vulnerable, there are two risks. Gradle could dow...

CVSS3: 6.6
debian
больше 3 лет назад

Gradle is a build tool. Dependency verification is a security feature ...

EPSS

Процентиль: 41%
0.00193
Низкий

6.6 Medium

CVSS3

4.4 Medium

CVSS3

Дефекты

CWE-829
CWE-347