The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.codehaus.groovy:groovy(Maven) | 1.7.0 | 2.4.4 | N/A |
| org.codehaus.groovy:groovy-all(Maven) | 1.7.0 | 2.4.4 | N/A |
CVSS Metrics