Headline
GHSA-3pjv-r7w4-2cf5: Grails data binding causes JVM crash and/or DoS
Impact
A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable.
Patches
Patches are available for Grails 3 and later.
Workarounds
No workaround is possible except to avoid data binding to request data.
References
Grails data binding causes JVM crash and/or DoS
Moderate severity GitHub Reviewed Published Dec 20, 2023 in grails/grails-core • Updated Dec 20, 2023