Vulnerabilities > Gopivotal

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-6521 Cross-Site Request Forgery (CSRF) vulnerability in Gopivotal Grails 2.0.6
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.
network
gopivotal CWE-352
6.8
2014-04-15 CVE-2014-2858 Path Traversal vulnerability in Gopivotal Grails and Grails-Resources
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.
network
low complexity
gopivotal CWE-22
5.0
2014-04-15 CVE-2014-2857 Permissions, Privileges, and Access Controls vulnerability in Gopivotal Grails and Grails-Resources
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request.
network
low complexity
gopivotal CWE-264
5.0
2014-04-15 CVE-2014-0053 Permissions, Privileges, and Access Controls vulnerability in Gopivotal Grails and Grails-Resources
The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request.
network
low complexity
gopivotal CWE-264
5.0