RHSA-2017:2486: Important: groovy security update
Groovy is an agile and dynamic language for the Java Virtual Machine, built upon Java with features inspired by languages like Python, Ruby, and Smalltalk. It seamlessly integrates with all existing Java objects and libraries and compiles straight to Java bytecode so you can use it anywhere you can use Java.Security Fix(es): It was found that a flaw in Apache groovy library allows remote code execution wherever deserialization occurs in the application. It is possible for an attacker to craft a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects are subject to this vulnerability. (CVE-2016-6814)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/groovyto a version that resolves this vulnerability.Fixed in 1.8.9-8.el7_4 - Upgrade
Upgrade
redhat/groovy-javadocto a version that resolves this vulnerability.Fixed in 1.8.9-8.el7_4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in groovy-1.8.9-8.el7_4.noarch.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in groovy-javadoc-1.8.9-8.el7_4.noarch.rpm
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:2486?
The severity of RHSA-2017:2486 is classified as important.
How do I fix RHSA-2017:2486?
To fix RHSA-2017:2486, update the groovy package to version 1.8.9-8.el7_4 or later.
Which packages are affected by RHSA-2017:2486?
The affected packages by RHSA-2017:2486 include groovy, groovy-javadoc, and their corresponding noarch versions.
What vulnerabilities does RHSA-2017:2486 address?
RHSA-2017:2486 addresses vulnerabilities that may allow an attacker to execute arbitrary code.
Is RHSA-2017:2486 applicable to all systems?
RHSA-2017:2486 is applicable to systems running the specified versions of the Red Hat groovy package.