GHSA-xphj-m9cc-8fmq

    Dashboard / Vulnerabilities / GHSA-xphj-m9cc-8fmq

    GHSA-xphj-m9cc-8fmq

    Published: 13 May 2022Last Modified: 17 Oct 2024
    Aliases:

    Summary: Deserialization of Untrusted Data in Groovy

    Details: When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.

    Affected packages

    Package

    Name: org.codehaus.groovy:groovy

    Purl: pkg:maven/org.codehaus.groovy/groovy

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.7.0
    Fixed -2.4.8

    Affected versions

    1.7.0
    1.7.1
    1.7.10
    1.7.11
    1.7.2
    1.7.3
    1.7.4
    1.7.5
    1.7.6
    1.7.7
    1.7.8
    1.7.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High