CVE-2023-46131

CVSS v3.1 7.5 (High)
75% Progress
EPSS 0.06 % (26th)
0.06% Progress
Affected Products 1
Advisories 1

Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.

Weaknesses
CWE-400
Uncontrolled Resource Consumption
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
GitHub, Inc.
Published Date
2023-12-21 00:15:25
(9 months ago)
Updated Date
2024-01-02 16:39:07
(8 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Grails prior 3.3.17 version cpe:2.3:a:grails:grails < 3.3.17
  Grails from 4.0.0 version and prior 4.1.3 version cpe:2.3:a:grails:grails >= 4.0.0 < 4.1.3
  Grails from 5.0.0 version and prior 5.3.4 version cpe:2.3:a:grails:grails >= 5.0.0 < 5.3.4
  Grails from 6.0.0 version and prior 6.1.0 version cpe:2.3:a:grails:grails >= 6.0.0 < 6.1.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...