cbcvebase.
CVE-2015-3253
published 2015-08-13

CVE-2015-3253: The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

Affected

85 ranges· showing 25
VendorProductVersion rangeFixed in
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy
apachegroovy

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL