GHSA-3pjv-r7w4-2cf5
Grails data binding causes JVM crash and/or other denial of service
Quick fix
GHSA-3pjv-r7w4-2cf5 — org.grails:grails-databinding: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.1.0</version> for org.grails:grails-databindingDetails
### Impact A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable.
### Patches Patches are available for Grails 3 and later.
### Workarounds No workaround is possible except to avoid data binding to request data.
### References
- [Blog post](https://grails.org/blog/2023-12-20-cve-data-binding-dos.html) - [Discussion](https://github.com/grails/grails-core/issues/13302) - [Mitre CVD record](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46131)
Are you affected?
Enter the version of the package you're using.
Affected packages
6.0.0Fixed in: 6.1.0# pom.xml: bump <version>6.1.0</version> for org.grails:grails-databinding5.0.0Fixed in: 5.3.4# pom.xml: bump <version>5.3.4</version> for org.grails:grails-databinding4.0.0Fixed in: 4.1.3# pom.xml: bump <version>4.1.3</version> for org.grails:grails-databinding2.0.0Fixed in: 3.3.17# pom.xml: bump <version>3.3.17</version> for org.grails:grails-databindingReferences
- https://github.com/grails/grails-core/security/advisories/GHSA-3pjv-r7w4-2cf5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-46131[ADVISORY]
- https://github.com/grails/grails-core/issues/13302[WEB]
- https://github.com/grails/grails-core/commit/74326bdd2cf7dcb594092165e9464520f8366c60[WEB]
- https://github.com/grails/grails-core/commit/c401faaa6c24c021c758b95f72304a0e855a8db3[WEB]
- https://github.com/grails/grails-core[PACKAGE]
- https://grails.org/blog/2023-12-20-cve-data-binding-dos.html[WEB]