Security Advisory

CVE-2016-6814

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-01-18 18:00:00
Last updated 2024-09-16 20:52:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.