CVE-2019-11065: Fedoraproject Fedora
Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
Affected products
- Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
- Gradle Gradle: from 1.4, up to and including 5.3.1
Published 2019-04-10. Last modified 2026-06-17.