Source: gradle Version: 4.4.1-8 Severity: important Tags: security upstream Forwarded: https://github.com/gradle/gradle/pull/10543 Control: found -1 4.4.1-6
Hi, The following vulnerability was published for gradle. CVE-2019-16370[0]: | The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 | algorithm, which might allow an attacker to replace an artifact with a | different one that has the same SHA-1 message digest, a related issue | to CVE-2005-4900. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-16370 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16370 [1] https://github.com/gradle/gradle/pull/10543 [2] https://github.com/gradle/gradle/commit/425b2b7a50cd84106a77cdf1ab665c89c6b14d2f Please adjust the affected versions in the BTS as needed. Regards, Salvatore