When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-794-1 | groovy security update |
EUVD |
EUVD-2022-5835 | When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability. |
Github GHSA |
GHSA-xphj-m9cc-8fmq | Deserialization of Untrusted Data in Groovy |
Ubuntu USN |
USN-4795-1 | Apache Groovy vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:52:30.155Z
Reserved: 2016-08-12T00:00:00
Link: CVE-2016-6814
No data.
Status : Modified
Published: 2018-01-18T18:29:00.233
Modified: 2024-11-21T02:56:53.077
Link: CVE-2016-6814
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN