← Vulnerability feed

Vulnerability record · CVE-2015-3253 · published 13 August 2015

CVE-2015-3253: Apache groovy injection vulnerability

Apache · Groovy

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

9.8 CVSS 3.0 Critical EPSS 41% · top 1.4% CWE-74 · Injection
9.8CVSS 3.0 base score, v2 7.5
41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
46References
17 Jun 2026Last modified by NVD

Description

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://groovy-lang.org/security.html Vendor Advisory
http://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.html MitigationThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-0066.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.securityfocus.com/archive/1/536012/100/0/threaded
http://www.securityfocus.com/bid/75919 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/91787 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1034815
http://www.zerodayinitiative.com/advisories/ZDI-15-365/ Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1376
https://access.redhat.com/errata/RHSA-2017:2486
https://access.redhat.com/errata/RHSA-2017:2596
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardi
https://security.gentoo.org/glsa/201610-01
https://security.netapp.com/advisory/ntap-20160623-0001/
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
http://groovy-lang.org/security.html Vendor Advisory
http://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.html MitigationThird Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2016-0066.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.securityfocus.com/archive/1/536012/100/0/threaded
http://www.securityfocus.com/bid/75919 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/91787 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1034815
http://www.zerodayinitiative.com/advisories/ZDI-15-365/ Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1376
https://access.redhat.com/errata/RHSA-2017:2486
https://access.redhat.com/errata/RHSA-2017:2596

Track CVE-2015-3253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed9.8CVE-2020-9546Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shad…EPSS 4.6%9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2016-6814Apache groovy deserialization of untrusted data vulnerabilityWhen an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…EPSS 17%9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed8.8CVE-2020-13936Apache velocity engine vulnerabilityAn attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as th…EPSS 23%8.8CVE-2019-2880Oracle retail store inventory management vulnerabilityVulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that…EPSS 1.5%8.8CVE-2020-11112Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2015-3253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.