Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:15:36
Updated: 2022-10-03T16:15:36
Reserved: 2022-10-03T00:00:00
Link: CVE-2012-2054
JSON object: View
NVD Information
Status : Analyzed
Published: 2012-04-05T14:55:05.840
Modified: 2012-04-05T14:55:05.840
Link: CVE-2012-2054
JSON object: View
Redhat Information
No data.
CWE