CVE-2019-16370

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
16/09/2019
Last modified:
21/07/2021

Description

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gradle:gradle:*:*:*:*:*:*:*:* 6.0 (excluding)