-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.gradle:gradle-core | maven | < 6.0 | 6.0 |
The commit diff shows the vulnerable line was explicitly changed from PGPUtil.SHA1 to PGPUtil.SHA512 in the createSignatureGenerator method. This directly correlates with the CVE description about reliance on SHA-1 for PGP signatures. The function's role in generating weak cryptographic signatures matches the vulnerability's root cause.
Ongoing coverage of React2Shell