Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

groovy 2.4.5 is outdated and vulnerabilities are reported with that version #60

Open
vaidyavi opened this issue Mar 11, 2024 · 1 comment

Comments

@vaidyavi
Copy link

groovy 2.4.5 is outdated and vulnerabilities are reported with 2.4.5 version.

Vulnerabilities reported :
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, an attacker could bake a special serialized object that will execute code directly when deserialized. All applications that rely on serialization and do not isolate the code that deserializes objects were subject to this vulnerability

Can we upgrade groovy version to 2.5.8?

@BrianGilreath
Copy link

BrianGilreath commented Mar 12, 2024

My man. The code hasn't seen any updates for over eight years. I'm going to unstar/unwatch this repo. I've moved on to this other project - https://github.com/perplexhub/rsql-jpa-specification

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants