OESA-2021-1309

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1309
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1309.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1309
Upstream
Published
2021-08-14T11:03:08Z
Modified
2025-08-12T05:04:25.378128Z
Summary
gradle security update
Details

Gradle is build automation evolved. Gradle can automate the building, testing, publishing, deployment and more of software packages or other types of projects such as generated static websites, generated documentation or indeed anything else. Gradle combines the power and flexibility of Ant with the dependency management and conventions of Maven into a more effective way to build. Powered by a Groovy DSL and packed with innovation, Gradle provides a declarative way to describe all kinds of builds through sensible defaults. Gradle is quickly becoming the build system of choice for many open source projects, leading edge enterprises and legacy automation challenges.

Security Fix(es):

The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.(CVE-2019-16370)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / gradle

Package

Name
gradle
Purl
pkg:rpm/openEuler/gradle&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-2.oe1

Ecosystem specific

{
    "src": [
        "gradle-4.4.1-2.oe1.src.rpm"
    ],
    "noarch": [
        "gradle-4.4.1-2.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / gradle

Package

Name
gradle
Purl
pkg:rpm/openEuler/gradle&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.1-2.oe1

Ecosystem specific

{
    "src": [
        "gradle-4.4.1-2.oe1.src.rpm"
    ],
    "noarch": [
        "gradle-4.4.1-2.oe1.noarch.rpm"
    ]
}