CVE

Id
55076  
CVE No.
CVE-2012-1833  
Status
Candidate  
Description
VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.  
Phase
Assigned (20120321)  
Votes
None (candidate not yet proposed)  
Comments