Lucene search

K
osvGoogleOSV:CVE-2019-16370
HistorySep 16, 2019 - 6:15 p.m.

CVE-2019-16370

2019-09-1618:15:12
Google
osv.dev
4

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.0%

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.0%