Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-09T23:37:04

Updated: 2019-08-19T02:06:06

Reserved: 2019-04-09T00:00:00


Link: CVE-2019-11065

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-10T00:29:00.243

Modified: 2023-11-07T03:02:39.093


Link: CVE-2019-11065

JSON object: View

cve-icon Redhat Information

No data.