PT-2015-6124 · Apache+2 · Apache Groovy+2

CVE-2015-3253

·

Publicado

2015-07-20

·

Atualizado

2024-08-06

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Groovy versions 1.7.0 through 2.4.3
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. This is related to the deserialization of untrusted data in Apache Groovy.
Recommendations For Apache Groovy versions 1.7.0 through 2.4.3, consider avoiding the deserialization of untrusted data as a temporary workaround until a patch is available. Restrict access to the MethodClosure class to minimize the risk of exploitation.

Correção

RCE

DoS

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2017_2486
CVE-2015-3253
DLA-274-1
GHSA-QG25-HGJV-CG9Q
MGASA-2015-0296
MGASA-2017-0333
RHSA-2017:2486
RHSA-2017:2596
RHSA-2017_2486
ZDI-15-365

Produtos afetados

Apache Groovy
Centos
Red Hat