Description
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4164 | The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900. |
Github GHSA |
GHSA-hhr2-f668-ff2w | Use of a weak cryptographic algorithm in Gradle |
Ubuntu USN |
USN-4858-1 | Gradle vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:10:41.829Z
Reserved: 2019-09-16T00:00:00.000Z
Link: CVE-2019-16370
No data.
Status : Modified
Published: 2019-09-16T18:15:12.190
Modified: 2024-11-21T04:30:35.267
Link: CVE-2019-16370
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN