CVE-2015-3253
published 2015-08-13CVE-2015-3253: The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial…
PriorityP269critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
42.98%
98.6th percentile
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Affected
85 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
| apache | groovy | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect deserialization of Groovy MethodClosure objects — the vulnerability is triggered when a crafted serialized object containing a MethodClosure is deserialized by an application with Groovy on the classpath. ↗
- →Monitor Java deserialization traffic (e.g. on Elasticsearch transport protocol port) for serialized Groovy MethodClosure payloads; CVE-2015-5377 / CVE-2015-3253 are claimed to be the same vulnerability exploited via the Elasticsearch transport protocol. ↗
- →Look for the presence of MethodClosure class in deserialized Java object streams; a readResolve() method throwing UnsupportedOperationException is the patch indicator — its absence in MethodClosure.java signals a vulnerable version. ↗
- →Flag applications running Apache Groovy versions 1.7.0 through 2.4.3 that accept serialized objects from remote sources over HTTP or network transport. ↗
- ·Affected versions are Apache Groovy 1.7.0 through 2.4.3; fixed in Groovy 2.4.4+ and Debian package groovy 2.4.6-1. ↗
- ·For Elasticsearch (CVE-2015-5377 / same vuln), Red Hat recommends firewalling Elasticsearch to trusted users only as a mitigation rather than patching. ↗
- ·The upstream patch in commit 09e9778e was later deemed insufficient; a second commit (716d3e67) was required, and CVE-2016-6814 tracks the follow-on incomplete-fix issue. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwpr-g44g-2pf3: ** DISPUTED ** Elasticsearch before 1
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2015-5377 [CRITICAL] CWE-74 GHSA-vwpr-g44g-2pf3: ** DISPUTED ** Elasticsearch before 1
** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability.
GHSA
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
ghsa·2022-05-13
CVE-2015-3253 [CRITICAL] CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
OSV
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
osv·2022-05-13
CVE-2015-3253 [CRITICAL] Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
OSV
CVE-2015-5377: ** DISPUTED ** Elasticsearch before 1
osv·2018-03-06·CVSS 9.8
CVE-2015-5377 [CRITICAL] CVE-2015-5377: ** DISPUTED ** Elasticsearch before 1
** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability.
OSV
CVE-2015-3253: The MethodClosure class in runtime/MethodClosure
osv·2015-08-13·CVSS 9.8
CVE-2015-3253 [CRITICAL] CVE-2015-3253: The MethodClosure class in runtime/MethodClosure
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) — CVE-2015-3253
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2015-3253 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) — CVE-2015-3253
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) vulnerability
CVE: CVE-2015-3253
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
groovy: remote execution of untrusted code in class MethodClosure
vendor_redhat·2015-07-16·CVSS 9.8
CVE-2015-3253 [CRITICAL] CWE-502 groovy: remote execution of untrusted code in class MethodClosure
groovy: remote execution of untrusted code in class MethodClosure
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
A flaw was discovered in the way applications using Groovy used the standard Java serialization mechanism. A remote attacker could use a specially crafted serialized object that would execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.
Mitigation: Apply the following patch on the MethodClosure class (src/main/org/codehaus/groovy/runtime/MethodClosure.java):
public class MethodClosure extends Closure {
Red Hat
elasticsearch: unspecified remote code execution vulnerability
vendor_redhat·2015-07-16·CVSS 9.8
CVE-2015-5377 [CRITICAL] elasticsearch: unspecified remote code execution vulnerability
elasticsearch: unspecified remote code execution vulnerability
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
Statement: This issue affects the versions of elasticsearch as shipped with Red Hat Satellite 6.x and Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Mitigation: For Satellite 6.x and Sam 1.x you can simply firewall elasticsearch to trusted users only (e.g. root, katello, fo
Debian
CVE-2015-3253: groovy - The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 thr...
vendor_debian·2015·CVSS 9.8
CVE-2015-3253 [CRITICAL] CVE-2015-3253: groovy - The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 thr...
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Scope: local
bookworm: resolved (fixed in 2.4.6-1)
bullseye: resolved (fixed in 2.4.6-1)
forky: resolved (fixed in 2.4.6-1)
sid: resolved (fixed in 2.4.6-1)
trixie: resolved (fixed in 2.4.6-1)
No detection rules found.
No public exploits indexed.
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosure
bugzilla·2015-07-16·CVSS 9.8
CVE-2015-3253 [CRITICAL] CVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosure
CVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosure
It was reported that when an application has Groovy on the classpath and that it uses standard Java serialization mechanim to communicate between servers, or to store local data, it is possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.
Mitigation:
Apply the following patch on the MethodClosure class (src/main/org/codehaus/groovy/runtime/MethodClosure.java):
public class MethodClosure extends Closure {
+ private Object readResolve() {
+ throw new UnsupportedOperationException();
+
}
Alternatively, you should make s
http://groovy-lang.org/security.htmlhttp://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0066.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/archive/1/536012/100/0/threadedhttp://www.securityfocus.com/bid/75919http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034815http://www.zerodayinitiative.com/advisories/ZDI-15-365/https://access.redhat.com/errata/RHSA-2016:1376https://access.redhat.com/errata/RHSA-2017:2486https://access.redhat.com/errata/RHSA-2017:2596https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardingsphere.apache.org%3Ehttps://security.gentoo.org/glsa/201610-01https://security.netapp.com/advisory/ntap-20160623-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://groovy-lang.org/security.htmlhttp://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0066.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/archive/1/536012/100/0/threadedhttp://www.securityfocus.com/bid/75919http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034815http://www.zerodayinitiative.com/advisories/ZDI-15-365/https://access.redhat.com/errata/RHSA-2016:1376https://access.redhat.com/errata/RHSA-2017:2486https://access.redhat.com/errata/RHSA-2017:2596https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardingsphere.apache.org%3Ehttps://security.gentoo.org/glsa/201610-01https://security.netapp.com/advisory/ntap-20160623-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2015-08-13
Published