CVE-2023-46131

MEDIUM

Grails <3.3.17, 4.1.3, 5.3.4, 6.1.0 - DoS

Title source: llm
STIX 2.1

Description

Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.

Scores

CVSS v3 6.5
EPSS 0.0054
EPSS Percentile 67.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
grails/grails < 3.3.17
org.grails/grails-databinding 6.0.0 - 6.1.0Maven
Published Dec 21, 2023
Tracked Since Feb 18, 2026