{"id":"CVE-2017-3160","details":"After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle executable is not safe. The severity of this issue is high due to the fact that the build scripts immediately start a build after Gradle has been fetched. Developers who are concerned about this issue should install version 6.1.2 or higher of Cordova-Android. If developers are unable to install the latest version, this vulnerability can easily be mitigated by setting the CORDOVA_ANDROID_GRADLE_DISTRIBUTION_URL environment variable to https://services.gradle.org/distributions/gradle-2.14.1-all.zip","modified":"2026-07-08T15:11:17.468294Z","published":"2018-02-01T21:29:00.197Z","references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95838"},{"type":"ADVISORY","url":"https://cordova.apache.org/announcements/2017/01/27/android-612.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/cordova-android","events":[{"introduced":"0"},{"fixed":"37ee3cdf81e810697e6780a4325a2cec4cce5968"}],"database_specific":{"cpe":"cpe:2.3:a:apache:cordova:*:*:*:*:*:android:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.1.2"}],"source":"CPE_RANGE"}}],"versions":["rel/6.1.1","6.1.1","rel/6.1.0","6.1.0","rel/StablePoC","StablePoC","CheckIn_node_modules","2.4.0","2.4.0rc1","2.2.0","2.2.0rc1","2.1.0","2.1.0rc2","2.1.0rc1","2.0.0","2.0.0rc1","1.9.0","1.8.1pre","1.8.0rc1","1.7.0","1.6.1","1.6.0","1.6.0rc1","1.5.0","1.5.0rc1","1.4.1","1.4.0","1.4.0rc1","1.2.0","1.1.0","0.9.5.1","0.9.5","0.9.4","0.9.3","0.9.2","0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-3160.json","vanir_signatures_modified":"2026-07-08T15:11:17Z","vanir_signatures":[{"target":{"file":"framework/src/org/apache/cordova/CordovaWebView.java"},"deprecated":false,"digest":{"line_hashes":["96936190387046404270703134661675771040","29879294918869099861397410465350151520","88333167400376117557867499877764349717","309572605990178499544204547139829020114"],"threshold":0.9},"id":"CVE-2017-3160-2b43499d","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/cordova-android/commit/37ee3cdf81e810697e6780a4325a2cec4cce5968"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}