Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.gradle:gradle-core(Maven) | 1.4 | 5.4.0 | N/A |
CVSS Metrics