Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2022-35912
Disclosure Date: July 19, 2022 (last updated October 07, 2023)
In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.
3
Attacker Value
Unknown
CVE-2023-46131
Disclosure Date: December 21, 2023 (last updated January 03, 2024)
Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or denial of service. Any Grails framework application using Grails data binding is vulnerable. This issue has been patched in version 3.3.17, 4.1.3, 5.3.4, 6.1.0.
0
Attacker Value
Unknown
CVE-2019-12728
Disclosure Date: June 04, 2019 (last updated November 27, 2024)
Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.
0
Attacker Value
Unknown
CVE-2018-1000529
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
0
Attacker Value
Unknown
CVE-2016-6521
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-2857
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to different researchers per ADT5.
0
Attacker Value
Unknown
CVE-2014-2858
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.
0
Attacker Value
Unknown
CVE-2014-0053
Disclosure Date: April 15, 2014 (last updated October 05, 2023)
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different researchers and different vulnerability types. See CVE-2014-2857 for the META-INF variant and CVE-2014-2858 for the directory traversal.
0
Attacker Value
Unknown
CVE-2012-1833
Disclosure Date: September 28, 2012 (last updated October 05, 2023)
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
0