7.5

CVE-2023-46131

Grails® data binding causes JVM crash and/or DoS

Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrailsGrails Version < 3.3.17
GrailsGrails Version >= 4.0.0 < 4.1.3
GrailsGrails Version >= 5.0.0 < 5.3.4
GrailsGrails Version >= 6.0.0 < 6.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.491
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

https://github.com/grails/grails-core/commit/74326bdd2cf7dcb594092165e9464520f8366c60
Patch
https://github.com/grails/grails-core/commit/c401faaa6c24c021c758b95f72304a0e855a8db3
Patch
https://github.com/grails/grails-core/issues/13302
Issue Tracking
https://github.com/grails/grails-core/security/advisories/GHSA-3pjv-r7w4-2cf5
Vendor Advisory
https://grails.org/blog/2023-12-20-cve-data-binding-dos.html
Vendor Advisory