Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-11065
HistoryApr 10, 2019 - 12:29 a.m.

Design/Logic Flaw

2019-04-1000:29:00
PRIOn knowledge base
www.prio-n.com
3

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.0%

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

CPENameOperatorVersion
fedoraeq28
fedoraeq29
fedoraeq30
gradlege1.4
gradlele5.3.1

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.0%