PatchSiren

Grails CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Grails CVE published 2017-02-27

CVE-2017-6344

CVE-2017-6344 is an XML External Entity (XXE) issue in Grails PDF Plugin 0.6. According to the CVE description, a crafted XML document can be used to read arbitrary files. NVD lists the issue as CVE-2017-6344 with CWE-611 and a CVSS 3.0 score of 5.9 (MEDIUM).