Severity
9.8CRITICAL
EPSS
69.7%
top 1.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 13

Description

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

Mavenorg.codehaus.groovy:groovy1.7.02.4.4
Mavenorg.codehaus.groovy:groovy-all1.7.02.4.4
NVDapache/groovy61 versions+60
Debiangroovy< 2.4.6-1+3

Patches

🔴Vulnerability Details

4
GHSA
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy2022-05-13
OSV
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy2022-05-13
CVEList
CVE-2015-3253: The MethodClosure class in runtime/MethodClosure2015-08-13
OSV
CVE-2015-3253: The MethodClosure class in runtime/MethodClosure2015-08-13

📋Vendor Advisories

4
Oracle
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Groovy) — CVE-2015-32532020-04-15
Red Hat
groovy: remote execution of untrusted code in class MethodClosure2015-07-16
Red Hat
elasticsearch: unspecified remote code execution vulnerability2015-07-16
Debian
CVE-2015-3253: groovy - The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 thr...2015

💬Community

1
Bugzilla
CVE-2015-3253 groovy: remote execution of untrusted code in class MethodClosure2015-07-16
CVE-2015-3253 (CRITICAL CVSS 9.8) | The MethodClosure class in runtime/ | cvebase.io