First published: Mon Sep 16 2019(Updated: )
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gradle Gradle | <6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16370 is a vulnerability in the PGP signing plugin in Gradle before version 6.0.
CVE-2019-16370 has a severity level of medium with a CVSS score of 5.9.
CVE-2019-16370 affects Gradle versions up to and excluding 6.0.
CVE-2019-16370 could allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest.
To fix CVE-2019-16370, upgrade to Gradle version 6.0 or later.