Описание
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.9 (включая)
Одно из
cpe:2.3:a:gopivotal:grails:*:*:*:*:*:*:*:*
cpe:2.3:a:gopivotal:grails:2.0.6:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00286
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
debian
около 9 лет назад
Cross-site request forgery (CSRF) vulnerability in Grails console (aka ...
CVSS3: 8.8
github
больше 3 лет назад
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.
EPSS
Процентиль: 52%
0.00286
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352