It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability.
Find out more about CVE-2016-6814 from the MITRE CVE dictionary dictionary and NIST NVD.
This issue affects the versions of groovy as shipped with Red Hat Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not ship groovy, as such they are not affected by this vulnerability.
CVSS3 Base Score | 9.6 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | Required |
Scope | Changed |
Confidentiality | High |
Integrity Impact | High |
Availability Impact | High |
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss Fuse 6.3 | RHSA-2017:0868 | 2017-04-03 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-maven33-groovy) | RHSA-2017:2596 | 2017-09-05 |
Red Hat Enterprise Linux 7 (groovy) | RHSA-2017:2486 | 2017-08-17 |
Red Hat JBoss A-MQ 6.3 | RHSA-2017:0868 | 2017-04-03 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-maven33-groovy) | RHSA-2017:2596 | 2017-09-05 |
Platform | Package | State |
---|---|---|
Red Hat Satellite 6 | groovy | Not affected |
Red Hat OpenShift Enterprise 2 | jenkins | Will not fix |
Red Hat JBoss Portal 5 | groovy | Under investigation |
Red Hat JBoss Operations Network 3 | groovy | Not affected |
Red Hat JBoss Fuse Service Works 6 | camel | Affected |
Red Hat JBoss Enterprise SOA Platform 5 | groovy | Will not fix |
Red Hat JBoss EAP 5 | groovy | Will not fix |
Red Hat JBoss Data Virtualization 6 | groovy | Affected |
Red Hat JBoss BRMS 5 | groovy | Will not fix |
RHEV Manager 3 | jasperreports-server-pro | Will not fix |