groovy: remote execution of untrusted code in class MethodClosure
Published Aug 13, 2015
9.8
CRITICALCVSS 3.0
EPSS 41.03%
Description
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
Affected products
No data.
Configuration 1
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.7.5
- 1.7.6
- 1.7.7
- 1.7.8
- 1.7.9
- 1.7.10
- 1.7.11
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.8.7
- 1.8.8
- 1.8.9
- 1.9.0
- 1.9.0
- 1.9.0
- 1.9.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.3.7
- 2.3.8
- 2.3.9
- 2.3.10
- 2.3.11
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
Configuration 2
- 3.1.1
- 3.1.2
- 4.1
- 5.1
- 5.2
- 15.0
- 13.0
- 13.1
- 13.2
- 14.0
- 14.1
- 15.0
- 13.2
- 14.0
- 14.1
Configuration 3
- 11.1.1.8.0
- 12.2.1
No data.
Red Hat Enterprise Linux 7
groovy-0:1.8.9-8.el7_4
Fixed · RHSA-2017:2486
Red Hat JBoss A-MQ 6.2
n/a
Fixed · RHSA-2015:2557
Red Hat JBoss Data Virtualization 6.2
groovy-all
Fixed · RHSA-2016:0066
Red Hat JBoss Fuse 6.2
n/a
Fixed · RHSA-2015:2556
Red Hat JBoss Fuse Service Works 6.2
n/a
Fixed · RHSA-2015:2558
Red Hat JBoss Operations Network 3.3
groovy-all
Fixed · RHSA-2016:0118
Red Hat JBoss SOA Platform 5.3
grovy-all
Fixed · RHSA-2016:1376
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-maven33-groovy-0:1.8.9-7.19.el6
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-maven33-groovy-0:1.8.9-7.19.el6
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-maven33-groovy-0:1.8.9-7.19.el7
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-maven33-groovy-0:1.8.9-7.19.el7
Fixed · RHSA-2017:2596
Red Hat BPM Suite 6
groovy-all
Not affected
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Affected
Red Hat JBoss BRMS 5
groovy-all
Will not fix
Red Hat JBoss Enterprise Application Platform 5
groovy-all
Will not fix
Red Hat JBoss Fuse Service Works 6
groovy-all
Affected
Red Hat JBoss Portal 6
groovy-all
Affected
Red Hat JBoss SOA Platform 4
groovy-all
Will not fix
Red Hat OpenShift Enterprise 2
jenkins
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | groovy-0:1.8.9-8.el7_4 | Fixed | RHSA-2017:2486 |
| Red Hat JBoss A-MQ 6.2 | n/a | Fixed | RHSA-2015:2557 |
| Red Hat JBoss Data Virtualization 6.2 | groovy-all | Fixed | RHSA-2016:0066 |
| Red Hat JBoss Fuse 6.2 | n/a | Fixed | RHSA-2015:2556 |
| Red Hat JBoss Fuse Service Works 6.2 | n/a | Fixed | RHSA-2015:2558 |
| Red Hat JBoss Operations Network 3.3 | groovy-all | Fixed | RHSA-2016:0118 |
| Red Hat JBoss SOA Platform 5.3 | grovy-all | Fixed | RHSA-2016:1376 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-maven33-groovy-0:1.8.9-7.19.el6 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-maven33-groovy-0:1.8.9-7.19.el6 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-maven33-groovy-0:1.8.9-7.19.el7 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-maven33-groovy-0:1.8.9-7.19.el7 | Fixed | RHSA-2017:2596 |
| Red Hat BPM Suite 6 | groovy-all | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Affected | n/a |
| Red Hat JBoss BRMS 5 | groovy-all | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | groovy-all | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | groovy-all | Affected | n/a |
| Red Hat JBoss Portal 6 | groovy-all | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | groovy-all | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | jenkins | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Apply the following patch on the MethodClosure class (src/main/org/codehaus/groovy/runtime/MethodClosure.java): public class MethodClosure extends Closure { + private Object readResolve() { + throw new UnsupportedOperationException(); + } Alternatively, you should make sure to use a custom security policy file (using the standard Java security manager) or make sure that you do not rely on serialization to communicate remotely.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (42 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 41.03% (0.41032) | 98.62th | v5 (v2026.06.15) |
| Sep 22, 2026 | 41.03% (0.41032) | 98.60th | v5 (v2026.06.15) |
| Sep 21, 2026 | 32.03% (0.32032) | 98.28th | v5 (v2026.06.15) |
| Sep 6, 2026 | 41.03% (0.41032) | 98.57th | v5 (v2026.06.15) |
| Sep 5, 2026 | 32.03% (0.32032) | 98.24th | v5 (v2026.06.15) |
| Aug 30, 2026 | 41.03% (0.41032) | 98.56th | v5 (v2026.06.15) |
| Aug 28, 2026 | 32.03% (0.32032) | 98.23th | v5 (v2026.06.15) |
| Aug 24, 2026 | 41.03% (0.41032) | 98.55th | v5 (v2026.06.15) |
| Aug 23, 2026 | 32.03% (0.32032) | 98.22th | v5 (v2026.06.15) |
| Jul 22, 2026 | 41.03% (0.41032) | 98.52th | v5 (v2026.06.15) |
| Jul 4, 2026 | 42.98% (0.42983) | 98.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 44.30% (0.44303) | 98.59th | v5 (v2026.06.15) |
| Jun 3, 2026 | 64.45% (0.64446) | 98.47th | v4 (v2025.03.14) |
| Apr 6, 2026 | 69.73% (0.69728) | 98.66th | v4 (v2025.03.14) |
| Mar 6, 2026 | 71.98% (0.71983) | 98.72th | v4 (v2025.03.14) |
| Mar 4, 2026 | 66.03% (0.66025) | 98.48th | v4 (v2025.03.14) |
| Mar 1, 2026 | 48.72% (0.48715) | 97.71th | v4 (v2025.03.14) |
| Feb 4, 2026 | 66.03% (0.66025) | 98.46th | v4 (v2025.03.14) |
| Feb 1, 2026 | 48.72% (0.48715) | 97.68th | v4 (v2025.03.14) |
| Jan 4, 2026 | 66.03% (0.66025) | 98.45th | v4 (v2025.03.14) |
| Jan 1, 2026 | 48.72% (0.48715) | 97.66th | v4 (v2025.03.14) |
| Dec 14, 2025 | 66.03% (0.66025) | 98.44th | v4 (v2025.03.14) |
| Dec 4, 2025 | 71.98% (0.71983) | 98.68th | v4 (v2025.03.14) |
| Dec 2, 2025 | 56.58% (0.56576) | 98.02th | v4 (v2025.03.14) |
| Dec 1, 2025 | 50.24% (0.50239) | 97.72th | v4 (v2025.03.14) |
| Nov 28, 2025 | 67.23% (0.67234) | 98.48th | v4 (v2025.03.14) |
| Nov 19, 2025 | 50.24% (0.50239) | 97.71th | v4 (v2025.03.14) |
| Apr 3, 2025 | 52.46% (0.52460) | 97.71th | v4 (v2025.03.14) |
| Mar 30, 2025 | 48.72% (0.48715) | 97.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 66.63% (0.66625) | 97.98th | v4 (v2025.03.14) |
| Mar 28, 2025 | 48.72% (0.48715) | 97.52th | v4 (v2025.03.14) |
| Mar 27, 2025 | 66.63% (0.66625) | 98.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 48.72% (0.48715) | 97.48th | v4 (v2025.03.14) |
| Dec 17, 2024 | 6.33% (0.06331) | 93.58th | v3 (v2023.03.01) |
| Dec 12, 2024 | 3.08% (0.03078) | 91.38th | v3 (v2023.03.01) |
| Apr 19, 2024 | 2.29% (0.02289) | 89.52th | v3 (v2023.03.01) |
| Sep 12, 2023 | 2.14% (0.02142) | 87.87th | v3 (v2023.03.01) |
| Mar 31, 2023 | 1.52% (0.01521) | 85.01th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.41% (0.01408) | 84.38th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.98% (0.07978) | 93.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.98% (0.07978) | 92.64th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.98% (0.07978) | 81.81th | v2 (v2022.01.01) |
References (30)
- http://groovy-lang.org/security.html x_refsource_CONFIRMVendor Advisory
- http://packetstormsecurity.com/files/132714/Apache-Groovy-2.4.3-Code-Execution.html x_refsource_MISCMitigationThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0066.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/oss-sec/2015/q3/121
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/536012/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/75919 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/91787 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034815 vdb-entryx_refsource_SECTRACK
- http://www.zerodayinitiative.com/advisories/ZDI-15-365 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2016:1376 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2486 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2596 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2015-3253 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1243934 Issue Tracking
- https://github.com/advisories/GHSA-qg25-hgjv-cg9q Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755 x_refsource_CONFIRM
- https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed%40%3Cnotifications.shardingsphere.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rbb8e16cc5acab183124572b655bdf5fe1d5b5f477dc267352426c7ed@%3Cnotifications.shardingsphere.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2015-3253
- https://security.gentoo.org/glsa/201610-01 vendor-advisoryx_refsource_GENTOO
- https://security.netapp.com/advisory/ntap-20160623-0001 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2015-3253
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html x_refsource_MISC
Change history (0)
No recorded changes yet.