VYPR
Vendor

Grails

Products
10
CVEs
8
Across products
10
Status
Private

Products

10

Recent CVEs

8
  • CVE-2022-35912CriJul 19, 2022
    risk 0.64cvss 9.8epss 0.02

    In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.

  • CVE-2022-41923CriNov 23, 2022
    risk 0.59cvss 9.1epss 0.02

    Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework…

  • CVE-2016-6521HigJan 23, 2017
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.

  • CVE-2019-12728HigJun 4, 2019
    risk 0.53cvss 8.1epss 0.01

    Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.

  • CVE-2014-3626HigMar 19, 2018
    risk 0.49cvss 7.5epss 0.02

    The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the…

  • CVE-2018-1000529MedJun 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.

  • CVE-2017-6344MedFeb 27, 2017
    risk 0.38cvss 5.9epss 0.01

    XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.

  • CVE-2023-46131MedDec 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in…