Vulnerability Name:

CVE-2019-16370 (CCN-167318)

Assigned:2019-09-16
Published:2019-09-16
Updated:2021-07-21
Summary:The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2019-16370

Source: XF
Type: UNKNOWN
gradle-cve201916370-sec-bypass(167318)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/gradle/gradle/commit/425b2b7a50cd84106a77cdf1ab665c89c6b14d2f

Source: CCN
Type: Gradle GIT Repository
signing plugin: use SHA512 instead of SHA1 when signing artifacts #10543

Source: MISC
Type: Exploit, Patch, Third Party Advisory
https://github.com/gradle/gradle/pull/10543

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-16370

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gradle:gradle:*:*:*:*:*:*:*:* (Version < 6.0)

  • Configuration CCN 1:
  • cpe:/a:gradle:gradle:5.6.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201916370
    V
    CVE-2019-16370
    2023-06-22
    oval:org.opensuse.security:def:8016
    P
    gradle-4.4.1-150200.3.10.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:3389
    P
    unixODBC-2.3.6-7.9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:1394
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important) (in QA)
    2022-06-27
    oval:org.opensuse.security:def:95019
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112350
    P
    gradle-4.4.1-7.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105865
    P
    Security update for poppler (Important)
    2021-12-01
    oval:org.opensuse.security:def:63011
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72730
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100845
    P
    glibc-locale-32bit-2.26-13.8.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101269
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1922
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:66811
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:66719
    P
    Security update for MozillaFirefox (Important)
    2021-04-01
    oval:org.opensuse.security:def:70167
    P
    Security update for xen (Important)
    2020-12-04
    oval:org.opensuse.security:def:72672
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94132
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107511
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1864
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117069
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62953
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:70062
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73502
    P
    gradle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49781
    P
    cvs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49835
    P
    gradle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73384
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.disco:def:2019163700000000
    V
    CVE-2019-16370 on Ubuntu 19.04 (disco) - medium.
    2019-09-16
    oval:com.ubuntu.bionic:def:2019163700000000
    V
    CVE-2019-16370 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-09-16
    oval:com.ubuntu.xenial:def:2019163700000000
    V
    CVE-2019-16370 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-09-16
    BACK
    gradle gradle *
    gradle gradle 5.6.2