In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35912.json"
}{
"cpe": [
"cpe:2.3:a:grails:grails:*:*:*:*:*:*:*:*",
"cpe:2.3:a:grails:grails:5.2.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.3.10"
},
{
"fixed": "3.3.15"
},
{
"introduced": "4.0.0"
},
{
"fixed": "4.1.1"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.1.9"
},
{
"introduced": "5.2.0"
},
{
"last_affected": "5.2.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35912.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"133658545622022813691893546492822193591",
"231968117220509831045687927920220568529",
"322518850141335907120383407016704122099",
"68221056247180651435663117672102194603"
],
"threshold": 0.9
},
"id": "CVE-2022-35912-07f35209",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/1e3c7077e0c773bd6f20f6f73d332e890abc0c50",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "86599955727034140749407227730922538923",
"length": 89
},
"id": "CVE-2022-35912-0fc45d9e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/b062a5cfe95835ea43217561db5ab8fa34aefe2b",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java",
"function": "testGrailsVersion"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"265527345752929269959675063536228266316",
"253657430198469265743706077559009248439",
"235959779190895364226641945778270050068",
"317079240568775686040492947509911246572"
],
"threshold": 0.9
},
"id": "CVE-2022-35912-25a5f26e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/2279cc53db82674fc3bf527b4c9a8a071ffd7942",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "337336054825846849060651794846366540003",
"length": 82
},
"id": "CVE-2022-35912-a40096a1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/1e3c7077e0c773bd6f20f6f73d332e890abc0c50",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java",
"function": "testGrailsVersion"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"168448992433160026276914504092498461111",
"212024600673281245820970122453290818013",
"24168885317386346339111550118646531829",
"57181071602607972446226234243744107833"
],
"threshold": 0.9
},
"id": "CVE-2022-35912-e8f2e693",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/b062a5cfe95835ea43217561db5ab8fa34aefe2b",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "294856197498714873664731451451100738900",
"length": 82
},
"id": "CVE-2022-35912-fb932cdf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/grails-core/commit/2279cc53db82674fc3bf527b4c9a8a071ffd7942",
"target": {
"file": "grails-core/src/test/groovy/grails/util/GrailsUtilTests.java",
"function": "testGrailsVersion"
}
}
]
"2026-08-27T08:14:50Z"