The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900. Reference: https://github.com/gradle/gradle/commit/425b2b7a50cd84106a77cdf1ab665c89c6b14d2f https://github.com/gradle/gradle/pull/10543
Created gradle tracking bugs for this issue: Affects: epel-6 [bug 1758994] Affects: fedora-all [bug 1758993]
This vulnerability is out of security support scope for the following products: * Red Hat JBoss Enterprise Web Server 3 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-16370