CVE-2019-11065: Fedoraproject Fedora

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Gradle Gradle: from 1.4, up to and including 5.3.1

Published 2019-04-10. Last modified 2026-06-17.