org.codehaus.groovy:groovy
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.codehaus.groovy:groovypage 1 of 1
- CVE-2015-3253CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.4.42015-08-13
vulnerable: 1.7.0 ... 2.4.3 (99 versions)
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
- CVE-2016-6814CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.4.82018-01-18
vulnerable: 1.7.0 ... 2.4.7 (103 versions)
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was…
- CVE-2020-17521MEDIUMCVSS 5.5EG 5.5✓ Fixed in 3.0.72020-12-07
vulnerable: 3.0.0 ... 3.0.6 (7 versions)
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on so…
Check whether org.codehaus.groovy:groovy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.codehaus.groovy:groovy CVEs against the assets you own.
Start Free Scan →