Back to search
CVE-2022-35912
Published: Jul 19, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://grails.org/blog/2022-07-18-rce-vulnerability.html
x_refsource_CONFIRM
https://github.com/grails/grails-core/issues/12626
x_refsource_CONFIRM
[oss-security] 20220720 Grails Framework Remote Code Execution Vulnerability, CVE-2022-35912
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now