VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2012-09-28T21:00:00

Updated: 2013-02-12T10:00:00

Reserved: 2012-03-21T00:00:00


Link: CVE-2012-1833

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2012-09-28T21:55:01.007

Modified: 2013-03-02T04:40:50.847


Link: CVE-2012-1833

JSON object: View

cve-icon Redhat Information

No data.

CWE