296,746
Total vulnerabilities in the database
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
| Software | From | Fixed in |
|---|---|---|
| gradle / gradle | 1.4 | 5.3.1.x |
| fedoraproject / fedora | 28 | 28.x |
| fedoraproject / fedora | 29 | 29.x |
| fedoraproject / fedora | 30 | 30.x |
org.gradle / gradle-core
|
1.4 | 5.4.0 |