← Back

Grails

grails

Vendor: Grails • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grails
1Grails
Nov 21, 2024
Dec 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data...Show more
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0. Show less
1Grails
1Grails
Nov 21, 2024
Jul 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by g...Show more
In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.Show less
1Grails
1Grails
Nov 21, 2024
Jun 4, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.