CVE-2012-1833: Medium severity SpringSource Grails vulnerability
Published Sep 28, 2012
·Updated
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.
Affected Software
16 affected components
SpringSource Grails<=1.3.7
SpringSource Grails=1.1.0
SpringSource Grails=1.1.1
SpringSource Grails=1.1.2
SpringSource Grails=1.2.0
SpringSource Grails=1.2.1
SpringSource Grails=1.2.2
SpringSource Grails=1.3.0
SpringSource Grails=1.3.1
SpringSource Grails=1.3.2
SpringSource Grails=1.3.3
SpringSource Grails=1.3.4
SpringSource Grails=1.3.5
SpringSource Grails=1.3.6
SpringSource Grails=2.0
SpringSource Grails=2.0.1
Remediation
Patch Available
Event History
Sep 28, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1833?
CVE-2012-1833 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-1833?
To fix CVE-2012-1833, upgrade to SpringSource Grails version 1.3.8 or 2.0.2 and later.
3
What are the potential impacts of CVE-2012-1833?
CVE-2012-1833 could allow remote attackers to bypass access restrictions and modify arbitrary object properties.
4
Which versions of Grails are affected by CVE-2012-1833?
Grails versions prior to 1.3.8 and all versions in the 2.x branch before 2.0.2 are affected by CVE-2012-1833.
5
What kind of attacks can exploit CVE-2012-1833?
Attackers can exploit CVE-2012-1833 by sending crafted request parameters that manipulate object properties.