Groovy: Remote code execution via deserialization
Published Jan 18, 2018
9.8
CRITICALCVSS 3.0
EPSS 17.24%
Description
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
groovy-0:1.8.9-8.el7_4
Fixed · RHSA-2017:2486
Red Hat JBoss A-MQ 6.3
n/a
Fixed · RHSA-2017:0868
Red Hat JBoss Data Virtualization 6.3
groovy
Fixed · RHSA-2017:0272
Red Hat JBoss Fuse 6.3
n/a
Fixed · RHSA-2017:0868
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-maven33-groovy-0:1.8.9-7.19.el6
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
rh-maven33-groovy-0:1.8.9-7.19.el6
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-maven33-groovy-0:1.8.9-7.19.el7
Fixed · RHSA-2017:2596
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
rh-maven33-groovy-0:1.8.9-7.19.el7
Fixed · RHSA-2017:2596
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Will not fix
Red Hat JBoss A-MQ 6
groovy
Affected
Red Hat JBoss BRMS 5
groovy
Will not fix
Red Hat JBoss Enterprise Application Platform 5
groovy
Will not fix
Red Hat JBoss Fuse 6
camel
Affected
Red Hat JBoss Fuse Service Works 6
camel
Affected
Red Hat JBoss Operations Network 3
groovy
Not affected
Red Hat JBoss Portal 5
groovy
Under investigation
Red Hat JBoss SOA Platform 5
groovy
Will not fix
Red Hat OpenShift Enterprise 2
jenkins
Will not fix
Red Hat Satellite 6
groovy
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | groovy-0:1.8.9-8.el7_4 | Fixed | RHSA-2017:2486 |
| Red Hat JBoss A-MQ 6.3 | n/a | Fixed | RHSA-2017:0868 |
| Red Hat JBoss Data Virtualization 6.3 | groovy | Fixed | RHSA-2017:0272 |
| Red Hat JBoss Fuse 6.3 | n/a | Fixed | RHSA-2017:0868 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-maven33-groovy-0:1.8.9-7.19.el6 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-maven33-groovy-0:1.8.9-7.19.el6 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-maven33-groovy-0:1.8.9-7.19.el7 | Fixed | RHSA-2017:2596 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-maven33-groovy-0:1.8.9-7.19.el7 | Fixed | RHSA-2017:2596 |
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Will not fix | n/a |
| Red Hat JBoss A-MQ 6 | groovy | Affected | n/a |
| Red Hat JBoss BRMS 5 | groovy | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | groovy | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | camel | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | camel | Affected | n/a |
| Red Hat JBoss Operations Network 3 | groovy | Not affected | n/a |
| Red Hat JBoss Portal 5 | groovy | Under investigation | n/a |
| Red Hat JBoss SOA Platform 5 | groovy | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | jenkins | Will not fix | n/a |
| Red Hat Satellite 6 | groovy | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of groovy as shipped with Red Hat Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not ship groovy, as such they are not affected by this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (45 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 17.24% (0.17239) | 97.01th | v5 (v2026.06.15) |
| Sep 22, 2026 | 17.24% (0.17239) | 96.96th | v5 (v2026.06.15) |
| Sep 21, 2026 | 15.85% (0.15852) | 96.79th | v5 (v2026.06.15) |
| Sep 6, 2026 | 17.24% (0.17239) | 96.89th | v5 (v2026.06.15) |
| Sep 5, 2026 | 15.85% (0.15852) | 96.72th | v5 (v2026.06.15) |
| Aug 30, 2026 | 17.24% (0.17239) | 96.88th | v5 (v2026.06.15) |
| Aug 28, 2026 | 15.85% (0.15852) | 96.70th | v5 (v2026.06.15) |
| Aug 24, 2026 | 17.24% (0.17239) | 96.86th | v5 (v2026.06.15) |
| Aug 23, 2026 | 15.85% (0.15852) | 96.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.55% (0.17550) | 96.74th | v5 (v2026.06.15) |
| Apr 24, 2026 | 24.32% (0.24315) | 96.11th | v4 (v2025.03.14) |
| Mar 4, 2026 | 25.71% (0.25712) | 96.13th | v4 (v2025.03.14) |
| Mar 1, 2026 | 4.12% (0.04118) | 88.45th | v4 (v2025.03.14) |
| Feb 4, 2026 | 25.71% (0.25712) | 96.10th | v4 (v2025.03.14) |
| Feb 1, 2026 | 4.12% (0.04118) | 88.39th | v4 (v2025.03.14) |
| Jan 4, 2026 | 25.71% (0.25712) | 96.06th | v4 (v2025.03.14) |
| Jan 1, 2026 | 4.12% (0.04118) | 88.34th | v4 (v2025.03.14) |
| Dec 14, 2025 | 25.71% (0.25712) | 96.04th | v4 (v2025.03.14) |
| Dec 4, 2025 | 24.32% (0.24315) | 95.87th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.76% (0.03757) | 87.67th | v4 (v2025.03.14) |
| Nov 28, 2025 | 24.32% (0.24315) | 95.87th | v4 (v2025.03.14) |
| Oct 6, 2025 | 2.80% (0.02801) | 85.58th | v4 (v2025.03.14) |
| Jul 4, 2025 | 3.95% (0.03949) | 87.85th | v4 (v2025.03.14) |
| Apr 3, 2025 | 2.95% (0.02947) | 85.27th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.95% (0.03949) | 87.28th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.09% (0.09085) | 87.63th | v4 (v2025.03.14) |
| Mar 28, 2025 | 3.95% (0.03949) | 87.29th | v4 (v2025.03.14) |
| Mar 27, 2025 | 9.09% (0.09085) | 91.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.95% (0.03949) | 87.58th | v4 (v2025.03.14) |
| Jan 30, 2025 | 4.65% (0.04647) | 92.57th | v3 (v2023.03.01) |
| Dec 17, 2024 | 3.30% (0.03302) | 91.13th | v3 (v2023.03.01) |
| Aug 18, 2024 | 5.09% (0.05092) | 93.06th | v3 (v2023.03.01) |
| Dec 29, 2023 | 3.66% (0.03659) | 90.78th | v3 (v2023.03.01) |
| Nov 28, 2023 | 2.65% (0.02645) | 89.24th | v3 (v2023.03.01) |
| Nov 3, 2023 | 1.44% (0.01440) | 85.17th | v3 (v2023.03.01) |
| Sep 7, 2023 | 2.03% (0.02029) | 87.52th | v3 (v2023.03.01) |
| Jul 21, 2023 | 2.40% (0.02403) | 88.43th | v3 (v2023.03.01) |
| Jul 8, 2023 | 2.24% (0.02241) | 87.99th | v3 (v2023.03.01) |
| Jun 11, 2023 | 2.61% (0.02612) | 88.80th | v3 (v2023.03.01) |
| May 8, 2023 | 2.80% (0.02799) | 89.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.04% (0.02039) | 87.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.90% (0.04900) | 89.44th | v2 (v2022.01.01) |
| Oct 15, 2022 | 4.90% (0.04900) | 89.04th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.77% (0.04771) | 88.16th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.77% (0.04771) | 74.54th | v2 (v2022.01.01) |
References (21)
- http://mail-archives.apache.org/mod_mbox/www-announce/201701.mbox/%3CCADRx3PMZ2hBCGDTY35zYXFGaDnjAs0tc5-upaVs6QN2sYUejyA%40mail.gmail.com%3E x_refsource_MISCPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0272.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/95429 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039600 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868 vendor-advisoryx_refsource_REDHATBroken Link
- https://access.redhat.com/errata/RHSA-2017:2486 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2596 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-6814 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1413466 Issue Tracking
- https://github.com/advisories/GHSA-xphj-m9cc-8fmq Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-6814
- https://security.gentoo.org/glsa/202003-01 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2016-6814
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html x_refsource_CONFIRM
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISC
Change history (0)
No recorded changes yet.