Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-1833

Опубликовано: 28 сент. 2012
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:springsource:grails:*:*:*:*:*:*:*:*
Версия до 1.3.7 (включая)
cpe:2.3:a:springsource:grails:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.5:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:1.3.6:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:2.0:*:*:*:*:*:*:*
cpe:2.3:a:springsource:grails:2.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00188
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.

EPSS

Процентиль: 41%
0.00188
Низкий

5 Medium

CVSS2

Дефекты

CWE-264