Release date:
Updated on:
Affected Systems:
VMWare Grails 2.x
VMWare Grails 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-1833
Grails is an open-source framework for rapid Web application development. Based on the Groovy programming language, Grails is built on Spring, Hibernate, and other standard Java frameworks, this will bring you an all-in-one framework that can achieve ultra-high productivity.
Grails 1.3.7, 2.0, and 2.0.1 encounter an error during data binding. Request parameters can be bound to the object instance without a whitelist or blacklist of attribute names. Attackers can update attributes illegally and bypass the target access restriction.
<* Source: vendor
Link: http://secunia.com/advisories/51113/
Http://support.springsource.com/security/cve-2012-1833
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SpringSource
------------
SpringSource has released a Security Bulletin (cve-2012-1833) and patches for this, please update to 1.3.8 and 2.0.2:
Cve-2012-1833: 29 March 2012: CVE-2012-1833: Grails data binding vulnerability
Link: http://support.springsource.com/security/cve-2012-1833