CVE-2022-35912

Name
CVE-2022-35912
Description
In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/grails/grails-core/security/advisories/GHSA-6rh6-x8ww-9h97
CONFIRM https://github.com/grails/grails-core/issues/12626
CONFIRM https://grails.org/blog/2022-07-18-rce-vulnerability.html
MLIST http://www.openwall.com/lists/oss-security/2022/07/20/4

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* grails >= 5.0.0 < 5.1.9
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* grails >= 4.0.0 < 4.1.1
cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:* grails >= 3.3.10 < 3.3.15
cpe:2.3:a:grails:grails:5.2.0:*:*:*:*:*:*:* grails == None == 5.2.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status