CVE-2019-11065 PUBLISHED

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

EPSS 0.35% · 57.2th percentile

Risk Scores

EPSS Score
0.35%
57.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgradle0, 2.5-3, 2.7-1
Ubuntu:Pro:18.04:LTSgradle0, 3.2.1-3build2, 3.2.1-4

Timeline

References

Open in Interactive Console →