CVE-2019-12728: Grails

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.

Affected products

  • Grails Grails: before 3.3.10 (fixed in 3.3.10)

Published 2019-06-04. Last modified 2026-06-17.