Description
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
Remediation
References
http://secunia.com/advisories/51113
http://support.springsource.com/security/cve-2012-1833
http://www.securityfocus.com/bid/55763
Related Vulnerabilities
CVE-2017-16008 Vulnerability in npm package i18next
CVE-2023-30543 Vulnerability in npm package @web3-react/eip1193
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5
CVE-2023-25722 Vulnerability in maven package com.veracode.jenkins:veracode-scan
CVE-2019-10785 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox