Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2019-15052 and CVE-2019-16370 fix with gradle update to 6.3 #288

Merged
merged 2 commits into from
May 11, 2020

Conversation

lanwen
Copy link
Collaborator

@lanwen lanwen commented Mar 20, 2020

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.
@lanwen lanwen requested a review from bsideup March 24, 2020 15:47
@lanwen lanwen changed the title CVE-2019-15052 and CVE-2019-16370 fix with gradle update CVE-2019-15052 and CVE-2019-16370 fix with gradle update to 6.2.2 Mar 24, 2020
@lanwen lanwen changed the title CVE-2019-15052 and CVE-2019-16370 fix with gradle update to 6.2.2 CVE-2019-15052 and CVE-2019-16370 fix with gradle update to 6.3 Apr 1, 2020
@bsideup bsideup added this to the next milestone May 11, 2020
@bsideup bsideup merged commit bc15831 into master May 11, 2020
@delete-merged-branch delete-merged-branch bot deleted the gradlew branch May 11, 2020 15:07
@bsideup bsideup added the dependencies Pull requests that update a dependency file label May 11, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants