Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2858

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:gopivotal:grails-resources:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails-resources:1.2.5:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:gopivotal:grails:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.4:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.3.6:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00239
Низкий

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

debian
почти 12 лет назад

Directory traversal vulnerability in the Resources plugin 1.0.0 before ...

github
больше 3 лет назад

Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.

EPSS

Процентиль: 47%
0.00239
Низкий

5 Medium

CVSS2

Дефекты

CWE-22