Groovy: Arbitrary code execution A vulnerability within serialization might allow remote attackers to execute arbitrary code. groovy 2020-03-07 2020-03-12 605690 remote 2.4.5

A multi-faceted language for the Java platform

It was discovered that there was a vulnerability within the Java serialization/deserialization process.

An attacker, by crafting a special serialized object, could execute arbitrary code.

There is no known workaround at this time.

Gentoo has discontinued support for Groovy. We recommend that users unmerge Groovy:

# emerge --unmerge "dev-java/groovy"
CVE-2016-6814 b-man b-man