CVE-2023-46131

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2023
Last modified:
02/01/2024

Description

Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* 3.3.17 (excluding)
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* 4.0.0 (including) 4.1.3 (excluding)
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* 5.0.0 (including) 5.3.4 (excluding)
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* 6.0.0 (including) 6.1.0 (excluding)