[MAVEN:GHSA-XPHJ-M9CC-8FMQ] Deserialization of Untrusted Data in Groovy

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.

Package Affected Version
pkg:maven/org.codehaus.groovy/groovy >= 1.7.0, <= 2.4.3
Package Fixed Version
pkg:maven/org.codehaus.groovy/groovy = 2.4.4
ID
MAVEN:GHSA-XPHJ-M9CC-8FMQ
Severity
critical
URL
https://github.com/advisories/GHSA-xphj-m9cc-8fmq
Published
2022-05-13T01:25:19
(2 years ago)
Modified
2023-01-27T05:02:10
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.codehaus.groovy/groovy org.codehaus.groovy groovy >= 1.7.0 <= 2.4.3
Fixed pkg:maven/org.codehaus.groovy/groovy org.codehaus.groovy groovy = 2.4.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...