MEDIUM
gradle: PGP signing plugin security bypass
Published Sep 16, 2019
5.9
MEDIUMCVSS 3.1
EPSS 1.03%
Description
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
Affected products
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2019-16370 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1758992 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4164 Advisory
- https://github.com/advisories/GHSA-hhr2-f668-ff2w Advisory
- https://github.com/gradle/gradle/commit/425b2b7a50cd84106a77cdf1ab665c89c6b14d2f x_refsource_MISCPatchThird Party Advisory
- https://github.com/gradle/gradle/pull/10543 x_refsource_MISCExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16370
- https://www.cve.org/CVERecord?id=CVE-2019-16370
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-16370 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1758992 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4164 | Advisory | |
| https://github.com/advisories/GHSA-hhr2-f668-ff2w | Advisory | |
| https://github.com/gradle/gradle/commit/425b2b7a50cd84106a77cdf1ab665c89c6b14d2f | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/gradle/gradle/pull/10543 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-16370 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-16370 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 16, 2019
Updated Aug 5, 2024
Reserved Sep 16, 2019
Link CVE-2019-16370
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4164 GHSA-HHR2-F668-FF2W Assigner mitre
Published Sep 16, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-4164