peter bassill · operator
$ cve CVE-2016-6814 JSON

CVE-2016-6814

9.8
CRITICAL · CVSS 3.0 · EPSS 17.2% (pctl 97)

Patch early

EPSS 17.2% — above the 10% action threshold.

Description

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.24% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-01-18
Last modified2026-06-17

Affected (2)

VendorProduct
apachegroovy
redhatenterprise linux server

References

→ the Explorer  ·  watch your stack  ·  NVD