CVE-2025-6384: Improper Control of Dynamically-Managed Code Resources in Crafter Studio
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.
By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution).
This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.craftercms:crafter-studioto a version that resolves this vulnerability.Fixed in 4.3.0 - Upgrade
Upgrade
CrafterCMS Crafter Studioto a version that resolves this vulnerability.Fixed in 4.2.2 - Compensating control
Restrict access to Crafter Studio to only trusted/authenticated developers to reduce the risk of Groovy Sandbox bypass leading to OS command execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6384?
The severity of CVE-2025-6384 is rated as critical due to the potential for remote code execution.
How do I fix CVE-2025-6384?
To fix CVE-2025-6384, upgrade Crafter Studio to version 4.3.0 or later.
Who is primarily affected by CVE-2025-6384?
Authenticated developers using versions of Crafter Studio between 4.0.0 and 4.3.0 are primarily affected by CVE-2025-6384.
What is the main risk associated with CVE-2025-6384?
The main risk associated with CVE-2025-6384 is the potential for attackers to execute arbitrary OS commands through Groovy sandbox bypass.
Can CVE-2025-6384 impact my server's security?
Yes, CVE-2025-6384 can significantly impact your server's security by allowing unauthorized access and control over the system.